diff --git a/src/Avalonia.Base/Platform/Storage/FileIO/StorageBookmarkHelper.cs b/src/Avalonia.Base/Platform/Storage/FileIO/StorageBookmarkHelper.cs index 4c43331803..cafbfdfa25 100644 --- a/src/Avalonia.Base/Platform/Storage/FileIO/StorageBookmarkHelper.cs +++ b/src/Avalonia.Base/Platform/Storage/FileIO/StorageBookmarkHelper.cs @@ -86,20 +86,19 @@ internal static class StorageBookmarkHelper Span decodedBookmark; - // Each base64 character represents 6 bits, but to be safe, - var arrayPool = ArrayPool.Shared.Rent(HeaderLength + base64bookmark.Length * 6); - if (Convert.TryFromBase64Chars(base64bookmark, arrayPool, out int bytesWritten)) - { - decodedBookmark = arrayPool.AsSpan().Slice(0, bytesWritten); - } - else - { - nativeBookmark = null; - return DecodeResult.InvalidFormat; - } + var arrayPool = ArrayPool.Shared.Rent(HeaderLength + base64bookmark.Length / 4 * 3); try { + // Each base64 character represents 6 bits, but to be safe, + if (!Convert.TryFromBase64Chars(base64bookmark, arrayPool, out int bytesWritten)) + { + nativeBookmark = null; + return DecodeResult.InvalidFormat; + } + + decodedBookmark = arrayPool.AsSpan(..bytesWritten); + if (decodedBookmark.Length < HeaderLength // Check if decoded string starts with the correct prefix, checking v1 at the same time. && !AvaHeaderPrefix.SequenceEqual(decodedBookmark.Slice(0, AvaHeaderPrefix.Length)))