VYPR
Medium severity4.6NVD Advisory· Published Oct 9, 2020· Updated Jun 17, 2026

CVE-2020-13626

CVE-2020-13626

Description

OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

Affected products

3
  • cpe:2.3:a:oneplus:app_locker:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oneplus:app_locker:*:*:*:*:*:*:*:*range: <=2020-10-06
    • (no CPE)
  • Range: <=2020-10-06

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.