Skip to content

App Lock Bypass via recent Apps. #190

@su7yian

Description

@su7yian

The App Lock mechanism fails to maintain a persistent "top-layer" lock during system transitions. By rapidly switching between the "Recents" menu and a protected application, the lock overlay is temporarily dismissed or fails to trigger, exposing the underlying app's UI.

This window of time is sufficient to:

Initiate app installations (as seen in the Play Store).

Toggle system settings.

View sensitive data in the app's history/preview cards.

Steps to Reproduce
Enable App Lock for a target app (e.g., Google Play Store or Settings).

Open the protected app; the PIN/Pattern overlay appears as expected.

Tap the Recents/History button (left soft key) to enter the multitasking view.

Rapidly switch back to the protected app or interact with the app's "Install" or "Toggle" buttons during the transition animation.

Observation: There is a ~1-second window where the app's UI is fully interactive before the App Lock overlay reappears. (As shown in video.)

Suggestions: If pin is not entered on first attempt then app should be removed from Recent Apps too.

Device Information
Device: Samsung A series.

Android Version: Android 15

App Lock Version: 2.4.3

Same method works for system settings too. You can install uninstall apps or Toogle settings.

VID-20260514-WA0000.mp4

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions