{"id":"CVE-2026-77875","published":"2026-09-19T00:16:57.193","lastModified":"2026-09-22T19:09:58.680","description":"The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root ADB shell or another local file-reading context with suitable storage access, can copy the SQLite database and media files directly without entering the vault passcode.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-922"],"vendors":[],"products":[],"references":[{"url":"https://fluidattacks.com/advisories/grin","tags":[]},{"url":"https://play.google.com/store/apps/details?id=com.macymind.calculatorlock","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}