Junglewise Threat Intelligence

CVE-2025-68709: SailingLab AppLock arbitrary JavaScript execution in BrowserMainActivity

CVE-2025-68709 · Severity: info · CVSS 0 · Published 2026-05-26

Executive brief

SailingLab AppLock, an Android application used to secure other apps with PINs or patterns, contains a security flaw in its built-in browser component. A local attacker or a malicious app on the same device can force the application to execute arbitrary web scripts. This could lead to unauthorized access to sensitive information, user interface spoofing, or potential elevation of privileges within the device.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in SailingLab AppLock version 4.3.8 for Android. The 'com.locker.app.privacy.browser.ui.BrowserMainActivity' component improperly handles VIEW intents containing 'javascript:' URIs. A local attacker or a malicious application on the same device can send a crafted intent to this activity to execute arbitrary JavaScript within the context of the app's browser. This can be exploited via adb commands or malicious third-party apps to achieve UI spoofing, data theft, or privilege escalation.

Affected products

  • SailingLab AppLock - Lock apps & Pin lock (com.alpha.applock) 4.3.8

Timeline

  • 2026-05-26: disclosed: NVD publication date

References

Related threats