VYPR

AppLock

by SailingLab

CVEs (2)

  • CVE-2025-68709MedMay 26, 2026
    risk 0.34cvss 5.2epss 0.00

    SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI…

  • CVE-2025-68708LowMay 26, 2026
    risk 0.16cvss 2.4epss 0.00

    SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure…