File theft via missing intent validation and over-broad FileProvider paths
Theft of arbitrary files via lack of intent validation and insecure provider paths in TTFViewerActivity.kt.
Theft of arbitrary files via lack of intent validation and insecure provider paths in TTFViewerActivity.kt.
Part 3: arbitrary code execution via third-party package context loading; vulnerabilities 16-18 listed as stubs.