LinkedIn Mobile App Lock Delay: A Subtle Security Risk I Identified




Affected Feature

LinkedIn mobile app's app lock feature. This requires password or biometric authentication whenever you reopen the app to protect your data.

How to Reproduce

  1. Open LinkedIn mobile app with app lock enabled
  2. Click any link inside the app that opens externally in Chrome (like a profile link)
  3. Browse in Chrome for a bit
  4. Switch back to LinkedIn
  5. The app lock doesn't trigger - you have full access for up to a minute without any authentication

The delay gives you a window where the app stays unlocked even though it should require immediate re-authentication.

Company Response

Reported to LinkedIn but marked as duplicate.

Comments

Popular posts from this blog

When an AI Search Engine Forgot Who It Was: A Bug Report That Changed Perplexity AI’s Identity

Understanding Android’s One-Time Permissions and Their Privacy Implications

Your Android Phone's Dirty Little Secret - Gemini