Vulnerability Description
AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents, an attacker can evade lockscreen verification and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/actuator/applock.passwordfingerprint.applockz
- https://github.com/actuator/applock.passwordfingerprint.applockz/blob/main/CVE-2
- https://play.google.com/store/apps/details?id=applock.passwordfingerprint.apploc
FAQ
What is CVE-2025-68711?
CVE-2025-68711 is a vulnerability with a CVSS score of 2.4 (LOW). AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an over...
How severe is CVE-2025-68711?
CVE-2025-68711 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-68711?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.