Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android AppLock JavaScript Injection Enabling Local Code Execution |
Wed, 27 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Android AppLock Allows JavaScript Execution via VIEW Intents | |
| Weaknesses | CWE-94 |
Wed, 27 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Actuator
Actuator com.alpha.applock |
|
| Vendors & Products |
Actuator
Actuator com.alpha.applock |
Tue, 26 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Android AppLock Allows JavaScript Execution via VIEW Intents | |
| Weaknesses | CWE-94 |
Tue, 26 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T17:25:23.526Z
Reserved: 2025-12-24T00:00:00.000Z
Link: CVE-2025-68709
Updated: 2026-05-27T17:25:15.679Z
Status : Deferred
Published: 2026-05-26T20:16:16.167
Modified: 2026-06-17T09:59:26.863
Link: CVE-2025-68709
No data.
OpenCVE Enrichment
Updated: 2026-05-28T00:00:14Z