Description
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 18 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode. | |
| Title | Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage | |
| First Time appeared |
Quantumtech Ltd
Quantumtech Ltd hide Photos - Secure Vault |
|
| Weaknesses | CWE-922 | |
| CPEs | cpe:2.3:a:quantumtech_ltd:hide_photos_-_secure_vault:4.1.0:*:android:*:*:*:*:* | |
| Vendors & Products |
Quantumtech Ltd
Quantumtech Ltd hide Photos - Secure Vault |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-09-18T23:29:28.221Z
Reserved: 2026-08-21T15:27:53.156Z
Link: CVE-2026-77875
No data.
Status : Received
Published: 2026-09-19T00:16:57.193
Modified: 2026-09-19T00:16:57.193
Link: CVE-2026-77875
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-922
Insecure Storage of Sensitive Information