Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can evade lockscreen verification and access protected apps (e.g., Chrome), resulting in information disclosure and privilege escalation.
History

Thu, 28 May 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local PIN Bypass via Overlay Manipulation in Easyelife App Lock

Wed, 27 May 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local Physical Bypass of Easyelife App Lock Overlay Allows Access to Protected Apps
Weaknesses CWE-287

Wed, 27 May 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Actuator
Actuator locker.app.safe.applocker
Vendors & Products Actuator
Actuator locker.app.safe.applocker

Tue, 26 May 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Physical Bypass of Easyelife App Lock Overlay Allows Access to Protected Apps
Weaknesses CWE-287

Tue, 26 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can evade lockscreen verification and access protected apps (e.g., Chrome), resulting in information disclosure and privilege escalation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-05-26T00:00:00.000Z

Updated: 2026-05-27T20:34:21.650Z

Reserved: 2025-12-24T00:00:00.000Z

Link: CVE-2025-68710

cve-icon Vulnrichment

Updated: 2026-05-27T20:34:12.644Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T20:16:16.317

Modified: 2026-05-27T21:16:16.963

Link: CVE-2025-68710

cve-icon Redhat

No data.