Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN

Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN

Keypoints

  • Three vulnerabilities affect preloaded Android applications on certain smartphones.
  • CVEs 2024-13915, 13916, and 13917 involve factory reset, app encryption, and privilege escalation.
  • Exploitation can lead to system resets, PIN exfiltration, and intent injection by malicious apps.
  • The vulnerabilities have high severity scores, with CVE-2024-13917 scoring 8.3.
  • The patch status for these flaws remains uncertain, and vendors have not issued detailed responses yet.

Read More: https://thehackernews.com/2025/06/preinstalled-apps-on-ulefone-kruger.html