PendingIntent default mutability flag undefined in Android 12+
0 reputation · 13 May 2021, 00:00 UTC
Since Android 12 the platform requires an explicit FLAG_IMMUTABLE or FLAG_MUTABLE when constructing a PendingIntent. The documentation states the requirement but does not define what happens when neither flag is supplied, leaving the default mutability ambiguous.
Developers need a reliable way to guarantee that a PendingIntent cannot be altered by other applications, especially when the intent carries sensitive extras or targets a privileged component. The current silent acceptance of a mutable intent creates a security gap and makes forward‑compatibility uncertain if the platform later changes the default to immutable.
What is the actual default mutability when no flag is provided on Android 12 and 13? Will a future release change that default to immutable? What is the recommended pattern to enforce immutability across all supported API levels without relying on undocumented behavior?