Add two specific callouts for the rule-of-2:
- Protobuf is similarly trusted for deserializing messages at high privilege (though it should be avoided if possible). - Many Android system APIs are Java facades around C++ and are not considered memory safe. Change-Id: Ia70520fc8b319a639b03cb78f1a664b478902528 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2486113 Commit-Queue: Robert Sesek <rsesek@chromium.org> Reviewed-by:Chris Palmer <palmer@chromium.org> Cr-Commit-Position: refs/heads/master@{#818667}
Showing
Please register or sign in to comment