Description
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
Published: 2026-08-10
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper export of Android application components in the AppLock application. Because certain components are exported without adequate access controls, a local, physical attacker can invoke these components and bypass the lock mechanism, gaining access to the protected application contents. The weakness is a classic case of improper access control, allowing unauthorized use of privileged functionality. This can lead to disclosure of confidential data stored within the locked app and may enable further exploitation of device functionalities if the app provides elevated permissions.

Affected Systems

Samsung Mobile Devices that have the AppLock application installed from earlier releases before the SMR Aug‑2026 Release 1 update. No specific version numbers are listed, but the issue affects all builds of AppLock bundled with Samsung mobile firmware prior to the mentioned release.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, with the exploit occurring in a local, physical context. The EPSS score is unavailable, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting limited or emerging exploitation data. The likely attack vector is a physical attacker who can trigger the exported components on the device, for example by using a custom intent or by exploiting the device’s interface. Once the app lock is bypassed, the attacker gains immediate unchecked access to the protected application and its data, which may contain sensitive personal information.

Generated by OpenCVE AI on August 10, 2026 at 09:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install or update to Samsung Mobile OS firmware SMR Aug‑2026 Release 1 or later to remove the exported component flaw
  • Verify that AppLock’s advanced settings do not expose exported components or allow direct intent access
  • Configure the device to require biometric or strong PIN authentication for all app locks and disable any physical unlock override options

Generated by OpenCVE AI on August 10, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Export of Android App Components Allows Physical Attackers to Bypass AppLock
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Weaknesses CWE-284
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:40:29.002Z

Reserved: 2025-12-11T01:33:35.822Z

Link: CVE-2026-21063

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T09:45:03Z

Weaknesses