Medium severityNVD Advisory· Published Sep 19, 2026
CVE-2026-77875
CVE-2026-77875
Description
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.