server/LockSettingsService.java in LockSettingsService in Android 6.x before 2016-07-01 allows attackers to modify the screen-lock password or pattern via a crafted application, aka internal bug 28163930.
No PoCs from references.
- https://github.com/nirdev/CVE-2016-3749-PoC