Description
A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page
Published: 2026-08-26
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A control logic defect in a specific built‑in webpage of the vivo Kids Mode application allows a user to view local gallery photos directly within the page. The flaw only exposes content that is already stored locally on the device, and it does not permit modification of files, execution of code, or remote compromise. The vulnerability is therefore a low‑severity local information disclosure.

Affected Systems

Vivo Kids Mode is the only product explicitly affected. No specific version numbers are listed in the advisory, so any installation of Kids Mode that includes the affected built‑in webpage is susceptible.

Risk and Exploitability

The CVSS score of 2.4 reflects the low impact nature of the flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. While the attack vector is likely local or through direct use of the built‑in webpage, the required conditions are minimal: the user must open the vulnerable page. Given the low severity and lack of publicly known exploitation, the overall risk is considered low.

Generated by OpenCVE AI on August 26, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official firmware or application update that addresses the control logic defect in Kids Mode
  • Disable or restrict access to the vulnerable built‑in webpage if an update is unavailable
  • Verify that the device’s local gallery permissions are configured to prevent unintended exposure to applications

Generated by OpenCVE AI on August 26, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Control Logic Defect in vivo Kids Mode Exposes Local Gallery Photos

Wed, 26 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page
Weaknesses CWE-653
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Vivo

Published:

Updated: 2026-08-26T13:59:11.317Z

Reserved: 2026-07-10T07:51:48.061Z

Link: CVE-2026-15366

cve-icon Vulnrichment

Updated: 2026-08-26T13:59:07.724Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T09:00:03Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization