Description
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's public method query() allows any other malicious application, without any granted Android system permissions, to exfiltrate the PIN code. Only version (version name: 13, version code: 33) was tested and confirmed to have this vulnerability. Application update was released in April 2025.
INFO
Published Date :
2025-05-30T15:16:03.066Z
Last Modified :
2025-10-03T09:01:35.255Z
Source :
CERT-PL
AFFECTED PRODUCTS
The following products are affected by CVE-2024-13916 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-13916.
| URL | Resource |
|---|---|
| https://cert.pl/en/posts/2025/05/CVE-2024-13915 |
|