Description
AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents, an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.
Published: 2026-05-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AppLockZ App Lock and Fingerprint Lock (version 4.2.11) contains a flaw that allows a local attacker with physical access to bypass the PIN lock. The application implements the lock as an overlay rather than relying on Android's secure authentication APIs, enabling an attacker to navigate exposed routes and evict lockscreen verification through advertisement or browser intents. This flaw, identified as an improper authentication weakness (CWE-287), permits an attacker to access protected applications such as Chrome, effectively elevating privileges and disclosing sensitive information.

Affected Systems

Systems affected include devices running AppLockZ App Lock and Fingerprint Lock 4.2.11 on Android. No vendor or product version list was supplied beyond the specific application version, so any Android device using this version is considered vulnerable.

Risk and Exploitability

The vulnerability is local, requiring physical access, but the exploitation path still poses a significant risk. With EPSS not available, the risk assessment relies on the attacker's ability to traverse the overlay. The absence of a KEV listing suggests that no widespread exploitation reports exist yet, yet the flaw's nature allows immediate privilege escalation once bypassed. Attackers can exploit the flaw by exploiting insecure navigation flows or intent‑based advertisement redirection, which the application treats as legitimate control paths.

Generated by OpenCVE AI on May 26, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install an updated or patched version of AppLockZ that uses secure authentication APIs instead of the overlay mechanism.
  • Verify that the access protection method leverages Android’s biometric or system lock mechanisms.
  • If no patch is available, avoid using AppLockZ as the primary lock mechanism or disable the overlay feature and use the device’s native lock screen.
  • Monitor for vendor releases and apply them promptly.

Generated by OpenCVE AI on May 26, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Attacker Can Bypass AppLockZ PIN Overlay to Access Protected Apps on Android
Weaknesses CWE-287

Tue, 26 May 2026 20:30:00 +0000

Type Values Removed Values Added
Description AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents, an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-26T19:55:38.950Z

Reserved: 2025-12-24T00:00:00.000Z

Link: CVE-2025-68711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-26T21:16:36.043

Modified: 2026-05-26T21:16:36.043

Link: CVE-2025-68711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T21:30:16Z

Weaknesses