HMS Push Kit安全漏洞问题咨询及修复方案确认
HMS Push Kit 安全漏洞解决方案
版本修复说明
你反馈的HmsMsgService无权限限制导致的CWE-925、MSTG-PLATFORM-1违规问题,官方已在HMS Push Kit 5.3.0.304及更高版本完成修复,调整了服务的权限校验逻辑,默认阻断第三方应用的非法访问,升级后无需额外配置即可解决该安全风险。
低版本临时规避方案
如果当前业务暂时无法升级SDK版本,可通过Android清单合并规则覆盖SDK的默认服务配置,手动添加签名级权限限制:
- 在应用
AndroidManifest.xml的根节点下自定义签名级权限:
<permission android:name="${applicationId}.PUSH_SERVICE_PERMISSION" android:protectionLevel="signature" />
- 重新声明
HmsMsgService,覆盖SDK的默认配置,添加权限校验:
<service android:name="com.huawei.hms.support.api.push.service.HmsMsgService" android:enabled="true" android:exported="true" android:permission="${applicationId}.PUSH_SERVICE_PERMISSION" android:process=":pushservice" android:directBootAware="true" tools:replace="android:permission"> <intent-filter> <action android:name="com.huawei.push.msg.NOTIFY_MSG" /> <action android:name="com.huawei.push.msg.PASSBY_MSG" /> </intent-filter> </service>
注意:需要在manifest根节点添加
xmlns:tools="http://schemas.android.com/tools"声明,才能正常使用tools:replace属性覆盖SDK配置。
适配说明
- 上述自定义配置不会影响Push Kit的正常消息接收功能,HMS Core系统服务调用该接口时符合签名校验规则,可正常访问
- 优先选择升级官方修复后的SDK版本,经过全量兼容性验证,无需额外适配即可解决问题
内容的提问来源于stack exchange,提问作者0405aj
相关产品推荐
相关产品推荐

