LinkedIn Mobile App Lock Delay: A Subtle Security Risk I Identified
Affected Feature
LinkedIn mobile app's app lock feature. This requires password or biometric authentication whenever you reopen the app to protect your data.
How to Reproduce
- Open LinkedIn mobile app with app lock enabled
- Click any link inside the app that opens externally in Chrome (like a profile link)
- Browse in Chrome for a bit
- Switch back to LinkedIn
- The app lock doesn't trigger - you have full access for up to a minute without any authentication
The delay gives you a window where the app stays unlocked even though it should require immediate re-authentication.
Company Response
Reported to LinkedIn but marked as duplicate.

Comments
Post a Comment