Impact
The vulnerability allows a local actor who can access the device's shared external storage to copy the vault's SQLite database and media files without having to provide the calculator‑style vault passcode. This results in the accidental exposure of sensitive data, including wallet records, media, and other confidential information stored by the vault, thereby compromising data confidentiality and user privacy. No remote attack vector is described, and the flaw is confined to scenarios where the attacker controls a local service with external storage permissions.
Affected Systems
The affected product is QuantumTech LTD's Hide Photos – Secure Vault, version 4.1.0, which runs on Android devices. The vulnerability exists only in this specific build.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium level of severity. Because the flaw requires local access to shared external storage, the exploitability is limited to users with an authorized non‑root ADB shell or other file‑reading context that can read the external storage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been widely observed exploited. Nevertheless, the impact on data confidentiality warrants prompt remediation, especially in environments where sensitive financial or personal data is stored.
OpenCVE Enrichment