{"id":"CVE-2026-84283","published":"2026-09-25T00:16:57.570","lastModified":"2026-09-25T17:17:15.520","description":"Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-922"],"vendors":[],"products":[],"references":[{"url":"https://fluidattacks.com/advisories/sanguisugabogg","tags":[]},{"url":"https://play.google.com/store/apps/details?id=com.securefolder.securevault","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}