Description
In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Information disclosure
Product status
15
References
android.googlesource.com/...83082b602ecff0f33fbb439ffc1d2da3
source.android.com/security/bulletin/2025-06-01