Junglewise Threat Intelligence

CVE-2026-77875: Hide Photos Secure vault insecure storage in shared external storage

CVE-2026-77875 · Severity: info · Published 2026-09-19

Executive brief

Hide Photos is an Android app that protects sensitive photos and documents behind a calculator-style passcode. However, the encrypted vault data and media files are stored unencrypted on the device's shared external storage, accessible to any app or user with file system access. An attacker with local access can bypass the passcode entirely by copying the SQLite database and media files directly, exposing all protected content.

Technical details

The vulnerability is an insecure data storage issue where the vault's authentication boundary (passcode) is not enforced at the storage layer. Protected media and wallet records are stored in plaintext or easily readable form on shared external storage (/sdcard or equivalent) rather than in app-private protected storage. A local attacker with ADB shell access, or any app granted storage permissions, can directly read and copy the database and media files without authentication, completely circumventing the passcode protection.

Affected products

  • Macymind Hide Photos Secure vault 4.1.0

Timeline

  • 2026-09-19: disclosed

References