Fix intent redirect bypass via selector in addCreatorToken

  When evaluating whether to append a creator token to an intent in
  ActivityManagerService.addCreatorToken, the system calculates a
  targetPackage to determine if isCreatorSameAsTarget is true. If
  the creator and target match, the token is omitted since the intent
  is seemingly staying within the same application.

  However, the previous logic failed to inspect the intent's selector.
  An attacker could bypass the token injection by setting the outer
  intent's package to their own app (tricking isCreatorSameAsTarget
  into evaluating as true), while embedding a selector that explicitly
  targets a victim's component. The Android routing framework
  (ComputerEngine) evaluates the selector's explicit component and
  routes the intent to the victim, successfully delivering the payload
  without a creator token attached.

  This change fixes the targetPackage calculation to correctly account
  for selectors. It now prioritizes the explicit component of the outer
  intent, followed by the explicit component or package of the selector,
  and finally falls back to the outer intent's package constraint.

Bug: 487147249
Test: Manually verifies the PoC of the vulnerability no longer works
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:dc03f183688231c065ac0e13ef10a00732ba7199
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:acbde95f3eec1695d5bf4fa52e4153ef1d1a708a
Merged-In: Idf5bdc7a5f9d1ca64b5504edc776685fd3bd3306
Change-Id: Idf5bdc7a5f9d1ca64b5504edc776685fd3bd3306
1 file changed