Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder. | |
| Title | FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass the PIN gate | |
| First Time appeared |
Flutecode
Flutecode secure Folder |
|
| Weaknesses | CWE-922 | |
| CPEs | cpe:2.3:a:flutecode:secure_folder:1.2:*:android:*:*:*:*:* | |
| Vendors & Products |
Flutecode
Flutecode secure Folder |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-09-24T23:41:34.147Z
Reserved: 2026-09-01T14:56:25.000Z
Link: CVE-2026-84283
No data.
Status : Received
Published: 2026-09-25T00:16:57.570
Modified: 2026-09-25T00:16:57.570
Link: CVE-2026-84283
No data.
OpenCVE Enrichment
No data.
Weaknesses