Information Leakage in Kruger&Matz Smartphones Due to App Lock Feature
CVE-2024-13916

6.9MEDIUM

Key Information:

Vendor
CVE Published:
30 May 2025

What is CVE-2024-13916?

The application 'com.pri.applock', pre-installed on Kruger&Matz smartphones, is vulnerable due to its handling of user-provided PIN codes. The application allows users to encrypt any app with a chosen PIN or biometric data; however, it exposes a public method in its content provider, which can be exploited by malicious applications. This flaw enables unauthorized apps to access the user’s encrypted PIN, potentially compromising the security of user data.

Affected Version(s)

com.pri.applock 13

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Szymon Chadam
.