CVE-2023-29733

HIGH

Lock Master 2.2.4 - Unauthorized SharedPreference Modification

Title source: llm
STIX 2.1

Description

The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of privilege attack.

Scores

CVSS v3 7.8
EPSS 0.0034
EPSS Percentile 25.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
dualspace/lock_master 2.2.4
Published May 30, 2023
Tracked Since Feb 18, 2026