jdamcd / android-crop

Android library project for cropping images
4.54k stars 1.07k forks source link

Oppo security loophole #280

Open adeshuniyal opened 6 years ago

adeshuniyal commented 6 years ago

Hi,

I am Adesh Uniyal and I have recognized a sort of proviso in the security of any social account or sharing application account in "Oppo F1s" running on working framework “ColorOS”.

In the mobile sets of Oppo F1s, a wide range of social accounts like whatsapp, facebook, messenger, gmail or some other sharing application of a client can be easily accessed to with no prerequisite of the pre-set passwords for the accompanying applications. And, these should be possible through photo gallery or even document supervisor of the versatile set by choosing any one picture or video in the gallery and select the share option through there on the off chance that you select whatsapp, messenger or gmail as the medium to share then it will directly lead you to the chose application without requesting the security key set on that application (password set through oppo settings that perhaps unique finger impression lock, pattern lock or digit lock).

In this manner, if these applications are locked through any sort of inbuilt lock settings (not the external applications utilized to set password on applications) they can be easily access through sharing any media file or text document through gallery or even file manager, if there is no password key set on file manager or gallery.