Impact
A pop‑up logic flaw in the Kids Mode feature allows a user to bypass password verification and launch Quick Apps that lie outside the controlled interface. The weakness is a credential handling issue (CWE‑841). Attackers can gain access to Quick Apps without being prompted for the device password. The unauthorized access is limited to the Quick Apps launched from Kids Mode and does not provide broader system compromise.
Affected Systems
vivo Kids Mode. No specific version information is available.
Risk and Exploitability
The CVSS score of 2.4 marks this as a low‑severity issue. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local user interaction with the pop‑up. Exploitation would require the user to interact with the flawed dialog, so the exposure is bounded to situations where the feature is enabled on a device.
OpenCVE Enrichment