MEDIUM 6.8 NVD

CVE-2026-77875

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.

References

Published: 2026-09-19 · Source: NVD · Feed updated: 2026-09-19
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-09-19 via NVD.
vulnfeed aggregates 14361 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.