A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.