Description
A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app.
Published: 2026-08-26
Score: 2.4 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A pop‑up logic flaw in the Kids Mode feature allows a user to bypass password verification and launch Quick Apps that lie outside the controlled interface. The weakness is a credential handling issue (CWE‑841). Attackers can gain access to Quick Apps without being prompted for the device password. The unauthorized access is limited to the Quick Apps launched from Kids Mode and does not provide broader system compromise.

Affected Systems

vivo Kids Mode. No specific version information is available.

Risk and Exploitability

The CVSS score of 2.4 marks this as a low‑severity issue. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local user interaction with the pop‑up. Exploitation would require the user to interact with the flawed dialog, so the exposure is bounded to situations where the feature is enabled on a device.

Generated by OpenCVE AI on August 26, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for vendor updates or patches for vivo Kids Mode and apply them as soon as available
  • Disable or turn off Quick Apps usage in Kids Mode until a fix is released
  • Monitor device logs for unauthorized Quick App launches to detect potential misuse

Generated by OpenCVE AI on August 26, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Kids Mode Password Bypass via Pop‑Up Logic Flaw

Wed, 26 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app.
Weaknesses CWE-841
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Vivo

Published:

Updated: 2026-08-26T06:45:35.488Z

Reserved: 2026-07-10T07:51:25.878Z

Link: CVE-2026-15365

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T08:30:03Z

Weaknesses
  • CWE-841

    Improper Enforcement of Behavioral Workflow