Android Forgot passcode allows bypass

Forums General Open Discussion Android Forgot passcode allows bypass

  • March 11, 2023 at 10:41 pm

    Hi, I’m using Cleanbrowsing v7.0 android app. I can set a passcode so that each time the user goto the Settings page, it shows a screen for them to input a passcode.

    On that page there is a “forgot passcode” button which opens a dialog to enter an admin key to reset the app.

    The problem is any value you enter will reset the app and disable the passcode that was set earlier. This allows the user to circumvent since they can enter any value to reset the app.

Tagged: