Three significant security vulnerabilities have been discovered in pre-installed applications on Ulefone and Krüger&Matz smartphones, potentially allowing malicious apps to perform unauthorized actions without user consent.
## The Vulnerabilities
**CVE-2024-13915 (CVSS: 6.9)**
A pre-installed factory test application on both brands’ devices exposes a service that allows any installed app to perform a factory reset without authorization, potentially causing data loss.
**CVE-2024-13916 (CVSS: 6.9)**
Krüger&Matz smartphones contain a pre-installed app lock application with a security flaw that allows malicious apps to extract PIN codes used for encrypting applications, compromising the protection mechanism.
**CVE-2024-13917 (CVSS: 8.3)**
The same app lock application on Krüger&Matz devices contains an exposed activity that permits malicious apps to inject system-level privileged intents into protected applications without requiring special permissions.
Security researchers note that the last two vulnerabilities can be chained together, with attackers first stealing the PIN code and then using it to bypass application protection.
CERT Polska, which published details about these flaws, credited security researcher Szymon Chadam for the responsible disclosure. The current patch status for these vulnerabilities remains unclear, with no official response yet from either manufacturer.
