216.73.216.6

CVE-2024-13917

· Published 30/05/2025 16:15 · Modified 30/05/2025 16:31

Labels: CVE-2024-13917 2025-05-30CVE-2024-13917CWE-926[email protected]

Essential information

Published
30/05/2025 16:15
Modified
30/05/2025 16:31
Author
Creator
CVSS
8.3 HIGH (v3) 8.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an arbitrary intent with system-level privileges to a protected application. One must know the protecting PIN number (it might be revealed by exploiting CVE-2024-13916) or ask the user to provide it. Vendor did not provide information about vulnerable versions. Only version (version name: 13, version code: 33) was tested and confirmed to have this vulnerability

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
kruger matz / applock cpe:2.3:a:kruger_matz:applock:13:*:*:*:*:*:*:*

References