PT-2025-23312 · Unknown · Com.Pri.Applock
Szymon Chadam
·
Published
2025-05-30
·
Updated
2025-06-13
·
CVE-2024-13917
CVSS v4.0
8.3
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
com.pri.applock version 13 (version code: 33)
Description
The issue allows a malicious application to inject an arbitrary intent with system-level privileges to a protected application. This can be done by exploiting the exposed "com.pri.applock.LockUI" activity, which does not require any granted Android system permissions. To successfully inject the intent, the malicious application must know the protecting PIN number or ask the user to provide it.
Recommendations
For version 13 (version code: 33), consider restricting access to the
com.pri.applock.LockUI activity to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Com.Pri.Applock