CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-12603

CVSS 9.8v3.1pub. 2024-12-13upd. 2026-04-15

A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.

🤖 AI Analysis
How it works

CWE-602 type error means that the password verification mechanism is implemented on the client side (mobile application) rather than on the server side or in a trusted environment. An attacker can exploit this logic flaw to bypass password verification without knowing it. This results in a lack of real protection for applications locked by AppLock.

Impact

An attacker with physical access to the device or with appropriate permissions can gain unauthorized access to applications protected by AppLock, bypassing password protection. This can lead to violation of confidentiality, integrity, and availability of data stored in these applications.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://security.tecno.com/SRC/securityUpdates

Who is affected

Mobile application com.transsion.applock — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References