CVE-2026-84283: FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass the PIN gate
Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, and open those files without authenticating to Secure Folder.
Affected Software
Event History
Frequently Asked Questions
Who can access files placed in the vault?
Any local application or file manager with access to the relevant Android shared-storage path can enumerate, copy, and open the vault files without authenticating to Secure Folder.
What access does an attacker need to exploit this issue?
The attacker needs local access through an Android application or file manager that can access the shared-storage location containing the vault files. No Secure Folder PIN authentication is required.
Are the affected vault files encrypted at rest?
No. Files selected for the password-protected vault are stored as unencrypted plaintext files in the Android shared-storage tree.