Executive brief
Easyelife App lock is an Android application designed to protect other apps with a PIN or fingerprint. A security flaw allows someone with physical access to the device to bypass this lock by navigating through specific advertisement or browser links. This could allow an unauthorized person to access sensitive information in protected apps like Chrome or email.
Technical details
Easyelife App lock (locker.app.safe.applocker) version 1.9.2 for Android implements its locking mechanism as a custom UI overlay rather than using Android's secure authentication APIs. This architectural flaw allows for an authentication bypass (CWE-288) via insecure navigation routes. Specifically, an attacker with physical access can exploit cascading interface flows—such as those triggered by advertisement or browser intents—to navigate away from the overlay without providing credentials. This enables unauthorized access to protected applications, leading to information disclosure and local privilege escalation.
Affected products
- Easyelife App lock (locker.app.safe.applocker) 1.9.2
Timeline
- 2026-05-26: disclosed: Initial disclosure date via MITRE/NVD