CVE-2019-15615
Description
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Changing the Android system clock to the past bypasses the lock protection in Nextcloud Android App 3.9.0.
Vulnerability
The Nextcloud Android App version 3.9.0 contains a vulnerability where a faulty check of the system time allows the lock protection to be bypassed. By setting the device's system clock to a time in the past, the application incorrectly evaluates the time-based lockout, enabling unauthorized access without proper authentication [1].
Exploitation
An attacker with physical access to the device or the ability to modify the system time can exploit this flaw. The steps involve changing the system time to an earlier date and then opening the Nextcloud app, which then fails to enforce the lock screen protection due to the incorrect time check [1].
Impact
Successful exploitation results in a bypass of the app's lock mechanism, granting the attacker access to the Nextcloud account and its associated files and data without authentication. This compromises the confidentiality of user data stored in the Nextcloud app [1].
Mitigation
Upgrade to a patched version of the Nextcloud Android App (3.9.1 or later). The fix was released on 2020-02-04. Users should update the app through the Google Play Store or other distribution channels. No workaround is available for version 3.9.0 [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Android/Android Appdescription
- Range: 3.9.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/747726mitrex_refsource_MISC
- nextcloud.com/security/advisory/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.