MEDIUM 6.8 NVD
CVE-2026-77875
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
References
- https://fluidattacks.com/advisories/grin
- https://play.google.com/store/apps/details?id=com.macymind.calculatorlock
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-09-19 via NVD.
vulnfeed aggregates 14361 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.