Impact
The vulnerability arises from improper export of Android application components in the AppLock application. Because certain components are exported without adequate access controls, a local, physical attacker can invoke these components and bypass the lock mechanism, gaining access to the protected application contents. The weakness is a classic case of improper access control, allowing unauthorized use of privileged functionality. This can lead to disclosure of confidential data stored within the locked app and may enable further exploitation of device functionalities if the app provides elevated permissions.
Affected Systems
Samsung Mobile Devices that have the AppLock application installed from earlier releases before the SMR Aug‑2026 Release 1 update. No specific version numbers are listed, but the issue affects all builds of AppLock bundled with Samsung mobile firmware prior to the mentioned release.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, with the exploit occurring in a local, physical context. The EPSS score is unavailable, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting limited or emerging exploitation data. The likely attack vector is a physical attacker who can trigger the exported components on the device, for example by using a custom intent or by exploiting the device’s interface. Once the app lock is bypassed, the attacker gains immediate unchecked access to the protected application and its data, which may contain sensitive personal information.
OpenCVE Enrichment