---
id: CVE-2025-68712
title: >-
  SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local
  attacker with physical access to bypass fingerprint or PIN authentication
summary: >-
  SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local
  attacker with physical access to bypass fingerprint or PIN authentication.
  Although the app integrates Android's biometric mechanisms, the lock is
  implemented with …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-285
  - CWE-287
published: '2026-05-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T16:10:00.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68712'
references:
  - url: 'https://github.com/actuator/com.sp.protector.free'
    label: cve@mitre.org
  - url: 'https://github.com/actuator/com.sp.protector.free/blob/main/CVE-2025-68712'
    label: cve@mitre.org
  - url: 'https://play.google.com/store/apps/details?id=com.sp.protector.free'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00136
epssPercentile: 0.02559
ingestedAt: '2026-10-05T16:25:58.371Z'
---

## Overview

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intents - an attacker can exit the lock interface without re-authentication and access protected apps (e.g., Chrome). This results in information disclosure and privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
