Junglewise Threat Intelligence

CVE-2025-68712: SpSoft AppLock auth bypass via custom overlay navigation

CVE-2025-68712 · Severity: info · CVSS 4.6 · Published 2026-05-27

Executive brief

SpSoft AppLock, an Android application used to protect other apps with a PIN or fingerprint, contains a security flaw that allows unauthorized access to protected content. An individual with physical access to the device can bypass the lock screen by triggering specific advertisement or browser sequences. This allows them to exit the security interface without providing a password, potentially exposing sensitive data in apps like Chrome or email clients.

Technical details

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android suffers from an authentication bypass (CWE-288) due to the use of a custom overlay lockscreen that is inconsistently enforced. A local attacker with physical access can exploit insecurely exposed routes and browsable activities. By triggering an advertisement flow or a browser intent while the device is in a protected state, the attacker can navigate through cascading interface flows to exit the lock interface. Upon returning from these external intents, the application fails to re-trigger the authentication overlay, granting the attacker full access to the underlying protected applications.

Affected products

  • SpSoft AppLock - Fingerprint (com.sp.protector.free) 7.9.40

Timeline

  • 2026-05-27: advisory: CVE-2025-68712 published by NVD/MITRE

References