CVE-2026-77875: CWE-922 Insecure Storage of Sensitive Information in QUANTUMTECH LTD Hide Photos - Secure vault
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
AI Analysis
Technical Summary
The vulnerability arises because the application's stored data is accessible via shared external storage, bypassing the vault passcode authentication. A local actor with authorized non-root ADB shell access or other local file-reading capabilities can directly copy the SQLite database and media files from the external storage. This constitutes insecure storage of sensitive information (CWE-922) as the data protection is not enforced at the storage level.
Potential Impact
An attacker with local access and appropriate permissions can obtain sensitive user data stored by the application without needing to authenticate through the vault passcode. This compromises the confidentiality of the stored photos and associated data. There is no indication of remote exploitation or privilege escalation beyond local access with storage read permissions.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should restrict local access to their devices and avoid granting unnecessary storage permissions to untrusted applications or users. Monitor vendor advisories for updates or fixes addressing this insecure storage issue.
CVE-2026-77875: CWE-922 Insecure Storage of Sensitive Information in QUANTUMTECH LTD Hide Photos - Secure vault
Description
The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.
CVSS v4.0
Score 6.8medium
Affected software
QUANTUMTECH LTD
Hide Photos - Secure vault
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the application's stored data is accessible via shared external storage, bypassing the vault passcode authentication. A local actor with authorized non-root ADB shell access or other local file-reading capabilities can directly copy the SQLite database and media files from the external storage. This constitutes insecure storage of sensitive information (CWE-922) as the data protection is not enforced at the storage level.
Potential Impact
An attacker with local access and appropriate permissions can obtain sensitive user data stored by the application without needing to authenticate through the vault passcode. This compromises the confidentiality of the stored photos and associated data. There is no indication of remote exploitation or privilege escalation beyond local access with storage read permissions.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should restrict local access to their devices and avoid granting unnecessary storage permissions to untrusted applications or users. Monitor vendor advisories for updates or fixes addressing this insecure storage issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Fluid Attacks
- Date Reserved
- 2026-08-21T15:27:53.156Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aadd12755bf5e2cf5b82060
Added to database: 09/19/2026, 00:02:47 UTC
Last enriched: 09/19/2026, 00:16:32 UTC
Last updated: 09/19/2026, 02:55:41 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.