CVE-2026-3674 | Freedom Factory dGEN1 up to 20260221 org.ethosmobile.ethoslauncher FakeAppProvider improper authorization
A vulnerability has been found in Freedom Factory dGEN1 up to 20260221 and classified as critical. Affected by this vulnerability is the function FakeAppProvider of the component org.ethosmobile.ethoslauncher. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-3674. The attack must be initiated from a local position. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.