SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation.
History

Tue, 26 May 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Android AppLock Allows JavaScript Execution via VIEW Intents
Weaknesses CWE-94

Tue, 26 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-26T19:13:56.394Z

Reserved: 2025-12-24T00:00:00.000Z

Link: CVE-2025-68709

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-26T20:16:16.167

Modified: 2026-05-26T20:19:21.240

Link: CVE-2025-68709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T20:30:15Z