How to gain unauthorized fingerprint access to an LG V10

Youtuber Matt OnYourScreen has discovered a pretty unsettling way to bypass all of the security on an LG V10 and potentially gain unlimited access to the device in the future. Any LG V10 running Nova Launcher is vulnerable to this attack, and all it takes is about 30 seconds of access to the device.

To be fair, the circumstances have to be pretty perfect to be able to pull off this trick on a V10. Here’s the breakdown of how it works, but bear in mind we are in no way condoning the malicious use of this work-around. Rather, we want to make it clear how easily this vulnerability can be exploited and demonstrate the steps necessary to protect your device from exploitation.


MediaTek development USBSee also: MediaTek-related bug leaves KitKat devices vulnerable7

Say someone lends you their smartphone for a minute or two. Maybe they’re showing off some cool app, maybe you’ve asked to make a call… either way, all you need is a few moments in which you have access to the V10’s screen and they aren’t paying attention.

If this person isn’t running Nova Launcher, the game’s up here. This vulnerability is only known to work on this particular launcher so far, so if your quarry is operating Google Now then they are safe from your malicious intent. However, if they are running Nova Launcher, you can tap the Home button while on the main home screen, then tap the Widgets option. Add a Nova Action widget to the home screen, and then choose the activity “com.lge.fingerprintsettings.”

youtu.be-oqNlBKoW_NY (1)

Source: Matt OnYourScreen

Pause here for a second, because this is where the vulnerability exists. Through the normal Settings menu, it’s impossible to access this particular activity before going through a security checkpoint and confirming either a fingerprint or PIN. However, since Nova is able to ignore the normal menu flow that leads to this screen, it creates a situation where a user can add their own fingerprint to the list of allowed fingerprints without ever proving that they have authorized access to the device.

The widget on the homescreen will now lead directly to fingerprint settings, and you can add your own fingerprint before deleting the widget, leaving little trace of your actions. Unless the addition fingerprint is noticed and deleted by the primary user, you will have unlimited access to the device from here on out.

youtu.be-oqNlBKoW_NY

Source: Matt OnYourScreen

There is, however, a very simple fix to prevent this exploit from working. The LG V10 only supports four fingerprint profiles. Any attempts to add a fifth profile will fail. Therefore if you want to protect this device from this vulnerability, all you have to do is scan in four fingerprints to fill up that list. Alternatively, you can use another launcher besides Nova.

youtu.be-oqNlBKoW_NY (2)

Source: Matt OnYourScreen

What do you think of this security settings bypass? Is this a problem that could exist on other phones running Nova Launcher? Let us know your opinions in the comments below!

Thanks, Matt OnYourScreen!


Android-malwareNext: Google bans 13 apps that secretly download other malware44

Latest posts

AI ‘content creators’ are getting harder to spot

Aitana Lopez, AI avatar by creative agency The Clueless. | Image: The Clueless This is The Stepback, a weekly newsletter breaking down one essential story...

JMGO’s N3 Ultimate projector is the new portable 4K champ

The N3 Ultimate doesn’t mind being off center. | Photo by Thomas Ricker / The Verge Sorry Anker: JMGO now makes my favorite flagship portable...

Galaxy S26 FE leaks in hands-on image with an updated, slightly funky camera bump

Ahead of its launch sometime later this year, Samsung’s Galaxy S26 FE has surfaced online early, showcasing a familiar, but slightly updated design. Read more...

The cutest games from the Wholesome Direct 2026 showcase

Every year at Summer Game Fest, nestled in between the splashy blockbuster showcases, the Wholesome Direct provides a nice change of pace. It's similarly...

GOG apologizes for emailing people Nazi symbols

Good ol' games? | Image: GOG GOG sent a newsletter about the game The End of the Sun on June 5th that included symbols associated...

The first Story-Rich showcase was packed with narrative-driven games

Fellow Traveller, the publisher behind games like Titanium Court and 1000xResist, just wrapped up its Story-Rich Showcase, which featured a bunch of narrative-driven indie...

Viaim RecDots earbuds are the sleekest AI recording tool yet

There are tons of earbuds and a growing number of AI-powered note-taking hardware, but what if they were combined into one neat package? That’s...

Kabuto Park captures the fleeting joy of summer vacation

There are a lot of games that remind me of summer - hot days in the backseat with a copy of Dragon Warrior III,...

Meta made its own AI-generated clickbait news feed

An AI-generated image of the royal family featuring two Queen Elizabeth IIs. | Image: Meta AI Facebook has long been filled with feeds of clickbait...

82-0 is the best basketball game, to hell with NBA 2K

Can you go undefeated? | Screenshot: The Verge 82-0 marries the stat nerd fun of fantasy basketball with instant gratification and a bit of dumb...