First published: Tue Nov 27 2018(Updated: )
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker bypass the FRP protection.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
<8.0.0.350\(c00\) | ||
Huawei Mate 9 Pro Firmware | <8.0.0.363\(c00\) | |
Huawei Mate 9 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7988 is a Factory Reset Protection (FRP) bypass vulnerability found in several smartphones.
An attacker can exploit CVE-2018-7988 by using a data cable to connect a smartphone to another smartphone and then performing a series of specific operations.
The severity of CVE-2018-7988 is medium with a CVSS score of 4.6.
Several smartphones, including Huawei Nova 2 Plus and Huawei Mate 9 Pro, are affected by CVE-2018-7988.
Please refer to the official Huawei security advisory for information on fixes for CVE-2018-7988.