CVE-2026-77875EPSS p7.4%
CVE-2026-77875CVE-2026-77875
Description
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Scoring
| EPSS | 0.18% probability of exploitation · percentile 7.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |