-
-
Notifications
You must be signed in to change notification settings - Fork 43
Closed
Description
I found a simple bypass by accident.
Steps to reproduce:
- Open a locked app so the lock screen shows
- Turn off the screen
- Turn it back on and unlock the phone
- Go back to the app
Result:
The lock screen does not show again and the app is fully accessible.
Expected:
The app should ask for authentication again.
Details:
- Device: Galaxy S8+
- Android: 9
- Backend Implementation: Usage Statistics (not Shizuku)
This basically means anyone who knows the phone unlock password can access locked apps. Not sure if this is specific to the Usage Statistics backend, but it is consistently reproducible on my device.
Let me know if you want more info or testing.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels