Description
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Published: 2026-09-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Apply Update
AI Analysis

Impact

The vulnerability allows a local actor who can access the device's shared external storage to copy the vault's SQLite database and media files without having to provide the calculator‑style vault passcode. This results in the accidental exposure of sensitive data, including wallet records, media, and other confidential information stored by the vault, thereby compromising data confidentiality and user privacy. No remote attack vector is described, and the flaw is confined to scenarios where the attacker controls a local service with external storage permissions.

Affected Systems

The affected product is QuantumTech LTD's Hide Photos – Secure Vault, version 4.1.0, which runs on Android devices. The vulnerability exists only in this specific build.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium level of severity. Because the flaw requires local access to shared external storage, the exploitability is limited to users with an authorized non‑root ADB shell or other file‑reading context that can read the external storage. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been widely observed exploited. Nevertheless, the impact on data confidentiality warrants prompt remediation, especially in environments where sensitive financial or personal data is stored.

Generated by OpenCVE AI on September 19, 2026 at 10:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Hide Photos – Secure Vault to a newer version that secures vault data storage.
  • If an update is unavailable, reconfigure the application to store the vault database and media files in the app’s internal, private storage instead of shared external storage.
  • Restrict external storage access by removing world‑read/write permissions from the vault’s data directory and disabling ADB shell access for non‑root users, thereby limiting local file‑reading contexts.

Generated by OpenCVE AI on September 19, 2026 at 10:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Title Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage
First Time appeared Quantumtech Ltd
Quantumtech Ltd hide Photos - Secure Vault
Weaknesses CWE-922
CPEs cpe:2.3:a:quantumtech_ltd:hide_photos_-_secure_vault:4.1.0:*:android:*:*:*:*:*
Vendors & Products Quantumtech Ltd
Quantumtech Ltd hide Photos - Secure Vault
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Quantumtech Ltd Hide Photos - Secure Vault
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-20T00:06:03.469Z

Reserved: 2026-08-21T15:27:53.156Z

Link: CVE-2026-77875

cve-icon Vulnrichment

Updated: 2026-09-20T00:05:58.590Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-19T00:16:57.193

Modified: 2026-09-22T19:09:58.680

Link: CVE-2026-77875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-922

    Insecure Storage of Sensitive Information