Information Leakage in Kruger&Matz Smartphones Due to App Lock Feature
CVE-2024-13916
6.9MEDIUM
What is CVE-2024-13916?
The application 'com.pri.applock', pre-installed on Kruger&Matz smartphones, is vulnerable due to its handling of user-provided PIN codes. The application allows users to encrypt any app with a chosen PIN or biometric data; however, it exposes a public method in its content provider, which can be exploited by malicious applications. This flaw enables unauthorized apps to access the user’s encrypted PIN, potentially compromising the security of user data.
Affected Version(s)
com.pri.applock 13