Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Video games for Change provides 5 new leaders to its board

    June 9, 2025

    Constructing clever AI voice brokers with Pipecat and Amazon Bedrock – Half 1

    June 9, 2025

    ChatGPT’s Reminiscence Restrict Is Irritating — The Mind Reveals a Higher Method

    June 9, 2025
    Facebook X (Twitter) Instagram
    UK Tech Insider
    Facebook X (Twitter) Instagram Pinterest Vimeo
    UK Tech Insider
    Home»AI Ethics & Regulation»Preinstalled Android Apps Discovered Leaking PINs and Executing Malicious Instructions
    AI Ethics & Regulation

    Preinstalled Android Apps Discovered Leaking PINs and Executing Malicious Instructions

    Declan MurphyBy Declan MurphyJune 2, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Preinstalled Android Apps Discovered Leaking PINs and Executing Malicious Instructions
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    On Might 30, 2025, CERT Polska coordinated the general public disclosure of three vital safety vulnerabilities affecting preinstalled Android purposes on smartphones from Ulefone and Krüger&Matz.

    These flaws, tracked as CVE-2024-13915, CVE-2024-13916, and CVE-2024-13917, expose customers to dangers starting from unauthorized gadget resets to theft of delicate PIN codes and privilege escalation by malicious purposes.

    Technical Breakdown of the Vulnerabilities

    The desk under summarizes the important thing particulars of the reported vulnerabilities:

    – Commercial –
    CVE ID Product Vendor(s) Affected Variations CWE Sort & Description
    CVE-2024-13915 com.pri.factorytest Ulefone, Krüger&Matz All via 1.0 CWE-926: Improper Export of Android Software Elements – Unrestricted entry to FactoryResetService permits manufacturing unit reset by any app.
    CVE-2024-13916 com.pri.applock Krüger&Matz 13 CWE-497: Publicity of Delicate System Info – Malicious apps can steal the consumer’s PIN through an exported content material supplier.
    CVE-2024-13917 com.pri.applock Krüger&Matz 13 CWE-926: Improper Export of Android Software Elements – Uncovered exercise permits privilege escalation with information of the PIN.

    Manufacturing facility Reset Service Publicity

    The com.pri.factorytest app, preinstalled on Ulefone and Krüger&Matz units, exposes the com.pri.factorytest.emmc.FactoryResetService service.

    On account of improper export controls, any put in utility can invoke this service to carry out a full manufacturing unit reset, probably wiping all consumer knowledge with out consent.

    This vulnerability is classed beneath CWE-926, which describes failures to correctly limit exported Android parts, permitting unauthorized app interplay.

    xml
    

    AppLock PIN Exfiltration

    On Krüger&Matz units, the com.pri.applock app is meant to safe different purposes utilizing a consumer PIN or biometric knowledge.

    Nevertheless, the com.android.suppliers.settings.fingerprint.PriFpShareProvider content material supplier exposes a public question() methodology, permitting any app, with out permissions, to extract the consumer’s PIN.

    It is a basic case of CWE-497, the place delicate system info is uncovered to unauthorized actors.

    javaCursor cursor = getContentResolver().question(
        Uri.parse("content material://com.android.suppliers.settings.fingerprint.PriFpShareProvider"),
        null, null, null, null);
    // Malicious app can learn PIN from cursor
    

    Intent Injection through Uncovered Exercise

    Additionally affecting com.pri.applock (model 13), An exported exercise com.pri.applock.LockUI might be invoked by any utility.

    A malicious app can inject arbitrary intents with system-level privileges into protected apps, offered it is aware of the PIN (which might be stolen through CVE-2024-13916).

    That is one other occasion of CWE-926—improper export of Android parts, resulting in potential privilege escalation and unauthorized entry.

    xml
    

    Coordinated Disclosure and Safety Implications

    CERT Polska managed the accountable disclosure course of, highlighting the significance of coordinated vulnerability administration within the Android ecosystem.

    These vulnerabilities display the essential want for strict export controls on Android parts and strong safety of delicate consumer knowledge.

    Customers of affected units ought to search firmware updates or mitigations from distributors and stay vigilant about app permissions and weird gadget habits.

    Discover this Information Fascinating! Comply with us on Google Information, LinkedIn, & X to Get Instantaneous Updates!

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    New Report Reveals Chinese language Hackers Tried to Breach SentinelOne Servers

    June 9, 2025

    New AI software targets vital gap in hundreds of open supply apps

    June 9, 2025

    Seraphic Safety Unveils BrowserTotal™ – Free AI-Powered Browser Safety Evaluation for Enterprises

    June 9, 2025
    Top Posts

    Video games for Change provides 5 new leaders to its board

    June 9, 2025

    How AI is Redrawing the World’s Electrical energy Maps: Insights from the IEA Report

    April 18, 2025

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025
    Don't Miss

    Video games for Change provides 5 new leaders to its board

    By Sophia Ahmed WilsonJune 9, 2025

    Video games for Change, the nonprofit group that marshals video games and immersive media for…

    Constructing clever AI voice brokers with Pipecat and Amazon Bedrock – Half 1

    June 9, 2025

    ChatGPT’s Reminiscence Restrict Is Irritating — The Mind Reveals a Higher Method

    June 9, 2025

    Stopping AI from Spinning Tales: A Information to Stopping Hallucinations

    June 9, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.