Impact
A control logic defect in a specific built‑in webpage of the vivo Kids Mode application allows a user to view local gallery photos directly within the page. The flaw only exposes content that is already stored locally on the device, and it does not permit modification of files, execution of code, or remote compromise. The vulnerability is therefore a low‑severity local information disclosure.
Affected Systems
Vivo Kids Mode is the only product explicitly affected. No specific version numbers are listed in the advisory, so any installation of Kids Mode that includes the affected built‑in webpage is susceptible.
Risk and Exploitability
The CVSS score of 2.4 reflects the low impact nature of the flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. While the attack vector is likely local or through direct use of the built‑in webpage, the required conditions are minimal: the user must open the vulnerable page. Given the low severity and lack of publicly known exploitation, the overall risk is considered low.
OpenCVE Enrichment