Impact
SailingLab AppLock (com.alpha.applock) implements its PIN lock as a screen overlay instead of using Android’s secure authentication APIs. A local attacker who has physical access to the device can navigate the app’s interface, exploiting exposed routes and advertisement or browser intents. This allows the attacker to bypass the lockscreen verification and gain access to protected applications such as Chrome, resulting in information disclosure and privilege escalation.
Affected Systems
The vulnerability affects SailingLab’s AppLock version 4.3.8 on Android devices. No other versions or vendor details are available in the current data set.
Risk and Exploitability
Exploitation requires only local, physical access to the device. The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in CISA’s KEV catalog. Therefore, the real‑world exploitation likelihood is uncertain but possible under the described local conditions.
OpenCVE Enrichment