biometric

AppWizard
June 2, 2025
On May 30, 2025, CERT Polska disclosed three security vulnerabilities affecting preinstalled Android applications on Ulefone and Krüger&Matz smartphones: CVE-2024-13915, CVE-2024-13916, and CVE-2024-13917. - CVE-2024-13915: The com.pri.factorytest application allows any app to invoke the FactoryResetService, enabling unauthorized factory resets due to improper export controls (CWE-926). - CVE-2024-13916: The com.pri.applock application exposes a public method that allows malicious apps to steal the user’s PIN, representing an exposure of sensitive system information (CWE-497). - CVE-2024-13917: The exported activity in com.pri.applock allows privilege escalation by enabling malicious apps to inject intents with system-level privileges if they have access to the compromised PIN (CWE-926). Users of affected devices are advised to seek firmware updates or mitigations from their vendors.
AppWizard
June 2, 2025
Significant vulnerabilities have been identified in pre-installed applications on Ulefone and Krüger&Matz Android smartphones, disclosed on May 30, 2025. Three vulnerabilities affect these devices, including CVE-2024-13915, which targets the com.pri.factorytest application, allowing unauthorized factory resets. CVE-2024-13916 and CVE-2024-13917 affect the com.pri.applock application on Krüger&Matz smartphones, enabling malicious apps to extract user PIN codes and inject arbitrary intents. These vulnerabilities stem from improper export of Android application components, allowing malicious applications to bypass Android’s permission model. Users are advised to check for updates and consider disabling vulnerable applications.
AppWizard
May 31, 2025
A bug affecting Google Wallet caused repeated authentication prompts for Wear OS users, which has now been patched by Google. Wear OS users can make Wallet payments without needing to authenticate if their smartwatch is unlocked and worn on their wrist. The issue was acknowledged by Google on May 20, and the fix was confirmed in a community post on May 29. The Google Wallet app on Wear OS has been updated to version 25.17, though it is unclear if the patch requires a manual update or was implemented server-side.
Winsage
May 29, 2025
Microsoft Windows 11 Pro is currently available for a reduced price of A, down from A0, until June 1. It features a streamlined interface, improved voice typing, robust search functionality, advanced security measures including biometric logins and encrypted authentication, integration with Microsoft Teams, Azure Active Directory for managing logins, Hyper-V for virtual machines, Windows Sandbox for secure file experimentation, touch navigation, and support for DirectX 12 Ultimate for gaming. The system requirements include at least 4GB of RAM and 40GB of hard drive space, and compatibility issues may arise for users unable to install updates via Windows Update.
Search