Impact
Gallery – Private Photo Vault 1.0.41 launches an HTTP server that is not protected by any authentication mechanism and exposes the contents of the device’s external storage, providing directory listings and the ability to download any file located under that storage hierarchy. This flaw is a CWE‑552 (Unrestricted File Download) that allows an attacker to read arbitrary files, potentially containing personal photos, videos, or other sensitive data.
Affected Systems
Brain Trust’s Gallery – Private Photo Vault for Android, version 1.0.41, is affected when installed on a device that is accessible over a local network. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of < 1% suggests that exploitation probability is very low, and the vulnerability is not listed in the CISA KEV catalog. Because the server can be reached from any machine on the local network without authentication, an attacker with access to the same network can simply connect to the exposed port 8080 and retrieve files. The absence of a required authentication layer means the risk is high for devices on unsecured or shared networks, even though public exploitation evidence is lacking.
OpenCVE Enrichment