Impact
SailingLab AppLock (com.alpha.applock) version 4.3.8 for Android includes a flaw in BrowserMainActivity that accepts VIEW intents containing javascript: URIs. When such an intent is processed, the embedded JavaScript is executed inside the application’s context, allowing a local attacker to run arbitrary code. This can lead to user interface spoofing or privilege escalation within the app, potentially compromising user data or enabling further malicious actions. The vulnerability is a direct result of unsafe navigation handling, enabling arbitrary code execution.
Affected Systems
The affected product is SailingLab AppLock (com.alpha.applock) version 4.3.8 for Android. No additional vendors or product versions are listed in the available data.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploits against it at this time. However, the nature of the flaw—local code execution—poses a significant risk if an attacker can inject a VIEW intent with a javascript: URI. Exploitation requires local access or the ability to influence intent transmission to the device, so the attack vector is local. The lack of a CVSS score means the severity cannot be quantified from available data, but the potential for complete compromise of the app’s execution environment warrants careful consideration.
OpenCVE Enrichment