PT-2026-43381 · Undefined · Undefined
Published
2026-05-26
·
Updated
2026-05-26
·
CVE-2025-68709
CVSS v3.1
5.2
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined