CVE-2020-13626: Oneplus App Locker

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

Affected products

  • Oneplus App Locker: up to and including 2020-10-06

Published 2020-10-09. Last modified 2026-06-17.