← Back to CVE search

CVE-2025-68711

AppLockZ App Lock and Fingerprint Lock

Description

AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android-s secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents, an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.

CVSS 2.4EPSS 0.186%Risk 0.24
View source
Published
2026-05-26 21:16:36
Affected versions
==4.2.11
Type
Installed app
Last modified
2026-07-23 11:10:00
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N