CVE-2024-13917
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an arbitrary intent with system-level privileges to a protected application. One must know the protecting PIN number (it might be revealed by exploiting CVE-2024-13916) or ask the user to provide it. Only version (version name: 13, version code: 33) was tested and confirmed to have this vulnerability. Application update was released in April 2025.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-926
- Published
- 2025-05-30
- Last modified
- 2026-03-13
Affected products
- Kruger&Matz com.pri.applock
Weakness type
Related vulnerabilities
- CVE-2026-20516 — In MiracastService, there is a possible escalation of privilege due to a confused deputy. This...
- CVE-2026-44965 — Six Android App Widget configuration activities in the Datadog Android application are declared...
- CVE-2026-47363 — The launcher activity AppActivity in the Datadog Android application is declared...
- CVE-2026-47361 — BubbleChatActivity in the Datadog Android application is declared android:exported="true" with no...
- CVE-2026-18604 — textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
- CVE-2026-20470 — In Telephony, there is a possible information disclosure due to a missing permission check. This...
- CVE-2026-57848 — Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation
- CVE-2026-12960 — An Improper Export of Android Application Components vulnerability in ASUS Router App allows a...