Description
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Published: 2026-09-18
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
Title Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage
First Time appeared Quantumtech Ltd
Quantumtech Ltd hide Photos - Secure Vault
Weaknesses CWE-922
CPEs cpe:2.3:a:quantumtech_ltd:hide_photos_-_secure_vault:4.1.0:*:android:*:*:*:*:*
Vendors & Products Quantumtech Ltd
Quantumtech Ltd hide Photos - Secure Vault
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Quantumtech Ltd Hide Photos - Secure Vault
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-18T23:29:28.221Z

Reserved: 2026-08-21T15:27:53.156Z

Link: CVE-2026-77875

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-19T00:16:57.193

Modified: 2026-09-19T00:16:57.193

Link: CVE-2026-77875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses