newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Pre-installed apps on ulefone, krüger, matz phones reset the device to reset apps and stole the pin
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Pre-installed apps on ulefone, krüger, matz phones reset the device to reset apps and stole the pin
Technology

Pre-installed apps on ulefone, krüger, matz phones reset the device to reset apps and stole the pin

June 3, 2025 2 Min Read
Share
Pre-installed apps on ulefone, krüger, matz phones reset the device to reset apps and stole the pin
SHARE

Preloaded Android applications on Ulefone and Krüger & Matz smartphones disclose three security vulnerabilities that allow apps installed on devices to perform a factory reset and encrypt the application.

A brief explanation of the three defects is as follows –

  • CVE-2024-13915 (CVSS score: 6.9) – The “com.pri.factorytest” application pre-installed on ulefone and Krüger & matz smartphones will publish “com.pri.factorytest.emmc.factoryreseStervice”.
  • CVE-2024-13916 (CVSS Score: 6.9) – The “com.pri.applock” application pre-installed on your Kruger & Matz smartphone allows you to encrypt your application using user-supplied PIN code or using biometric data. The app also exposes the “query()” method of the “com.android.providers.settings.fingerprint.prifpshareprovider” content provider. This will remove the PIN code for malicious apps already installed on your device by other means.
  • CVE-2024-13917 (CVSS score: 8.3) – The “com.pri.applock” application pre-installed on Kruger & Matz smartphones has released the “com.pri.applock.lockui” activity.

To take advantage of CVE-2024-13917, you need to know the protection pin number to the enemy, but you can chain it with CVE-2024-13916 to leak the PIN code.

Cert Polska, who detailed the vulnerability, was praised by Szymon Chadam for his responsible disclosure. However, the exact patch status of these defects remains unknown. Hacker News has asked both Ulefone and Krüger & Matz for additional comments and will update the story if there is a reply.

See also  How AI agents are transforming the education sector: See Kira Learning and Beyond
Share This Article
Facebook Twitter Copy Link
Previous Article Isaiah Pacheco has bulged in hopes of recapturing his form after the 2024 season of injury. Isaiah Pacheco has bulged in hopes of recapturing his form after the 2024 season of injury.
Next Article How good is Real Research’s AI agent? In the deep search bench report How good is Real Research’s AI agent? In the deep search bench report
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code
Technology

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code

2 Min Read
Malicious Peep, NPM and Ruby Packages exposed in an ongoing open source supply chain attack
Technology

Malicious Peep, NPM and Ruby Packages exposed in an ongoing open source supply chain attack

9 Min Read
DOJ seizes 145 domains tied to the BidencashCarding Marketplace of Global Takedown
Technology

DOJ seizes 145 domains tied to the BidencashCarding Marketplace of Global Takedown

3 Min Read
Fake recruiters email target CFOs using legal netbird tools in six global regions
Technology

Fake recruiters email target CFOs using legal netbird tools in six global regions

9 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?