Impact
The vulnerability arises from improper export of Android application components in the AppLock application, which is distributed on Samsung mobile firmware. Certain components are exported without adequate access controls, allowing a local, physical attacker to invoke these components and bypass the lock mechanism. This weakness is a form of improper authorization (CWE‑926) and can lead to disclosure of confidential data stored within the locked app. The impact is that an attacker who can physically access the device can gain immediate access to the app’s protected contents.
Affected Systems
Samsung Mobile Devices that have the AppLock application installed from releases before the SMR Aug‑2026 Release 1 firmware update. All builds of AppLock bundled with Samsung mobile firmware prior to that release are affected; no specific version numbers are listed.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, with the exploit occurring only in a local, physical context. The EPSS score of <1% shows an extremely low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a physical attacker who can trigger the exported components on the device, for example by using a custom intent or by manipulating the device's interface. Once the lock is bypassed, the attacker gains unchecked access to the protected application and its data, which may contain sensitive personal information.
OpenCVE Enrichment