In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
Framework
{ "type": "ID", "spl": "2022-01-01", "severity": "High" }