Bypass screen lock by using shortcuts when fingerprint sensor has lost fingerprints

REPRODUCIBILITY: When fingerprint sensor is unresponsive
OS VERSION: 4.4.0.64 (Vanha Rauma)
HARDWARE: Xperia 10ii
UI LANGUAGE: English & Finnish at least
REGRESSION: Not tested on other versions

DESCRIPTION:

When my fingerprint sensor once again for the n+1:th time lost my saved fingerprints, I found out that when using the optional shortcuts on top or when using gesture to get the camera open from the bottom, one can bypass the security code and access the device.

When I added a lost fingerprint back, the bypass no longer worked, so it seems to be related the situation when fingerprints are suddenly missing.

PRECONDITIONS:

Fingerprint sensor being unresponsive and all previously given fingerprints are lost from the settings

STEPS TO REPRODUCE:

CASE A)

  1. Wait for the fingerprint sensor to stop working once again
  2. Go to settings > lock screen > add shortcut > select application (for example clock)
  3. Allow the screen to lock itself and go dark
  4. Wake screen, do not unlock it
  5. swipe down to select the previously created shortcut
  6. swipe left > swipe up
  7. Phone is unlocked without fingerprint or code

CASE B)

  1. Wait for the fingerprint sensor to stop working once again
  2. Go to settings > gestures > enable “quick access to camera”
  3. Allow the screen to lock itself and go dark
  4. Wake screen, do not unlock it
  5. swipe up from the camera symbol to quick access camera
  6. swipe left > swipe up
  7. Phone is unlocked without fingerprint or code

EXPECTED RESULT:

Phone asking for security code to unlock the phone

ACTUAL RESULT:

Phone is unlocked without asking security code

MODIFICATIONS:

ADDITIONAL INFORMATION:

Settings → System → Display → Sleep after: was 2 minutes, then tried with 30 seconds with the same results
Settings → System → Device lock → Automatic locking → No Delay

1 Like

Could you please add to “Additional information” few settings.

  • Settings → System → Display → Sleep after
  • Settings → System → Device lock → Automatic locking

Pondering if really locked as display turning off does not mean that device lock kicks in. Only if automatic locking “No delay” then device lock is activated right after display is dimmed.

Added the information requested to my original post.