First published: Fri Dec 13 2019(Updated: )
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 10 Firmware | <9.0.0.167\(c00e85r2p20t8\) | |
Huawei Mate 10 | ||
Huawei Mate 10 Firmware | <9.0.0.159\(c432e4r1p9t8\) | |
Huawei Mate 10 Firmware | <9.0.0.177\(c185e2r1p12t8\) | |
Huawei Mate 10 Firmware | <9.0.0.159\(c636e2r1p12t8\) | |
Huawei Mate 10 Pro Firmware | <9.0.0.167\(c00e87r2p15t8\) | |
Huawei Mate 10 pro | ||
Huawei Mate 10 Pro Firmware | <9.0.0.159\(c185e2r1p13t8\) | |
Huawei Mate 10 Pro Firmware | <9.0.0.161\(c432e4r1p11t8\) | |
Huawei Mate 10 Pro Firmware | <9.0.0.159\(c636e2r1p13t8\) | |
Huawei Honor V10 Firmware | <9.0.0.156\(c00e156r2p14t8\) | |
Huawei Honor V10 | ||
Huawei Honor V10 Firmware | <9.0.0.159\(c432e4r1p9t8\) | |
Huawei Honor V10 Firmware | <9.0.0.159\(c636e3r1p12t8\) | |
Huawei Changxiang 7s Firmware | <9.1.0.107\(c00e107r2p8t8\) | |
Huawei Changxiang 7s | ||
Huawei P-smart Firmware | <9.1.0.119\(c636e5r1p1t8\) | |
Huawei P-smart | ||
Huawei P-smart Firmware | <9.1.0.130\(c432e8r1p5t8\) | |
Huawei Changxiang 8 Plus Firmware | <9.1.0.111\(c00e111r1p6t8\) | |
Huawei Changxiang 8 Plus | ||
Huawei Y9 2018 Firmware | <9.1.0.115\(c432e5r1p1t8\) | |
Huawei Y9 2018 | ||
Huawei Y9 2018 Firmware | <9.1.0.120\(c636e5r1p1t8\) | |
Huawei Honor 9 Lite Firmware | <9.1.0.113\(c00e111r2p10t8\) | |
Huawei Honor 9 Lite | ||
Huawei Honor 9 Lite Firmware | <9.1.0.118\(c636e4r1p1t8\) | |
Huawei Honor 9 Lite Firmware | <9.1.0.118\(c185e4r1p4t8\) | |
Huawei Honor 9 Lite Firmware | <9.1.0.121\(c432e4r1p3t8\) | |
Huawei Honor 9i Firmware | <9.1.0.121\(c432e4r1p3t8\) | |
Huawei Honor 9i | ||
Huawei Honor 9i Firmware | <9.1.0.106\(sp53c636e2r1p4t8\) | |
Huawei Mate 9 Firmware | <9.0.1.158\(c432e6r1p8t8\) | |
Huawei Mate 9 | ||
Huawei Mate 9 Firmware | <9.0.1.159\(c636e6r1p8t8\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5264 is an information disclosure vulnerability in certain Huawei smartphones.
Certain Huawei smartphones including Mate 10, Mate 10 Pro, Honor V10, Changxiang 7S, P-smart, Changxiang 8 Plus, Y9 2018, Honor 9 Lite, Honor 9i, and Mate 9 are affected by CVE-2019-5264.
CVE-2019-5264 has a severity score of 4.6 which is classified as medium severity.
CVE-2019-5264 can lead to information disclosure as the software does not handle certain information of applications locked by applock in a rare condition.
To fix CVE-2019-5264, Huawei has released a security advisory with the necessary steps to mitigate the vulnerability. Please refer to the Huawei Security Advisory for more details.