The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Quantumtech_Ltd Hide_Photos_-_Secure_Vault
cpe:2.3:a:quantumtech_ltd:hide_photos_-_secure_vault:4.1.0:*:android:*:*:*:*:*
|
— | — |