In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/2cd616165c6de4d523637cd84eb0c7490415beb6" ], "severity": "Moderate", "types": [ "ID" ], "spl": "2021-06-01", "vanir_signatures": [ { "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "createNoCredentialsPermissionNotification" }, "id": "PUB-A-177931355-530f30a5", "deprecated": false, "digest": { "function_hash": "13955884187775680452074247685830298299", "length": 1140.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/2cd616165c6de4d523637cd84eb0c7490415beb6", "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "doNotification" }, "id": "PUB-A-177931355-de5d347c", "deprecated": false, "digest": { "function_hash": "245953299183076540288114581199226225348", "length": 1223.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/2cd616165c6de4d523637cd84eb0c7490415beb6", "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" }, "id": "PUB-A-177931355-f7759722", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "299383651173671348817543944941812103312", "256989136395354121258640567185123162473", "196639853982148962795096014224859608594", "269835483600688645271061730841538456826", "254814283906023037685745410800905479751", "336598113711868789328123905093133525669", "114574420740669496987600946882937790505", "12084265700894750695441376242007765274" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/2cd616165c6de4d523637cd84eb0c7490415beb6", "signature_type": "Line", "signature_version": "v1" } ] }