Skip to content

Tamper protection bypass in the Security & privacy settings tab #238

@krypciak

Description

@krypciak

Have you checked it on Project Progress ? yes

Describe the bug
A clear and concise description of what the bug is.

When tamper protection is activated, it can be bypassed.

To Reproduce
Steps to reproduce the behavior:

  1. Open Settings
  2. Open Security & privacy (either through the button or through search)
  3. Click the Remove access button
  4. Accessibility permission gets removed right after pressing the button

Expected behavior
A clear and concise description of what you expected to happen.

I don't think it's possible to just block the button, the whole page would need to be blacklisted.

Screenshots
If applicable, add screenshots to help explain your problem.

Image Image Image

Additional context
Mindful's version - v1.3.5+149 db-v9
Android version - 16
Device manufacturer - Pixel 8a
Device OS/ROM - GrapheneOS

Add any other context about the problem here.

I got a notification that told me to review my privacy settings and ended up on this screen.
The Remove access button is also on the Security & privacy->Privacy Controls (note that blocking only Security & privacy will not suffice since Privacy Controls can be also accessed through search)
Thanks for the gorgeous looking app ❤️

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions