Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass in SpSoft AppLock via Inconsistent Overlay and Intent Navigation | |
| Weaknesses | CWE-284 |
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-287 |
|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass in SpSoft AppLock via Inconsistent Overlay and Intent Navigation | |
| Weaknesses | CWE-284 |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can exit the lock interface without re-authentication and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-28T15:51:34.786Z
Reserved: 2025-12-24T00:00:00.000Z
Link: CVE-2025-68712
Updated: 2026-05-28T15:51:25.321Z
Status : Deferred
Published: 2026-05-27T17:16:29.063
Modified: 2026-05-28T17:16:19.543
Link: CVE-2025-68712
No data.
OpenCVE Enrichment
Updated: 2026-05-28T19:45:25Z