Passcode bypass on Talk Android app

Disclosed: 2023-01-09 05:49:57 By ctulhu To nextcloud
Low
Vulnerability Details
## Summary: It is possible to bypass the passcode protection in nextcloud android talk by clicking the notification of a message. Talk App Android version: ```15.0.2 RC1``` ## Steps To Reproduce: 1. Create two users 1. Using User A login it to the web interface while User B on Talk App Android 1. Using User B setup the passcode protection in settings 1. Using User A send a message to User B 1. Wait for the notification and click it ## Supporting Material/References: █████ ## Impact To exploit this the attacker needs to have a physical access to the target's device which makes it severity to medium. Due to the bypass of passcode an attacker is able to access the user's nextcloud files and view conversations. ████████
Actions
View on HackerOne
Report Stats
  • Report ID: 1784645
  • State: Closed
  • Substate: resolved
  • Upvotes: 25
Share this report