Executive brief
SailingLab AppLock is an Android application used to protect other apps on a device with a PIN or pattern. A security flaw allows someone with physical access to the phone to bypass this lock by interacting with advertisements or browser links that appear over the lock screen. This could allow an unauthorized person to access sensitive apps like Chrome or private messages even when they are supposed to be locked.
Technical details
SailingLab AppLock (com.alpha.applock) version 4.3.8 fails to use Android's secure authentication APIs, instead implementing its lock screen as a custom UI overlay. This implementation is vulnerable to an authentication bypass (CWE-288) where an attacker with physical access can exploit 'cascading interface flows.' By triggering and interacting with exposed activity routes—such as clicking through advertisements or browser intents that launch from the overlay—an attacker can navigate away from the lock screen and gain access to protected applications. This effectively evades the intended security controls, leading to unauthorized information disclosure and privilege escalation on the device.
Affected products
- SailingLab AppLock - Lock apps & Pin lock (com.alpha.applock) 4.3.8
Timeline
- 2026-05-26: disclosed: Vulnerability disclosed via NVD and researcher GitHub repository.