First published: Mon Oct 19 2020(Updated: )
HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with common privilege, successful exploit could cause code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 30 Firmware | <10.1.0.150\(c00e136r5p3\) | |
HUAWEI Mate 30 | ||
Huawei P30 Firmware | <10.1.0.160\(c00e160r2p11\) | |
HUAWEI P30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9263 is a use after free vulnerability that affects HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11).
The severity of CVE-2020-9263 is high with a severity score of 7.8.
CVE-2020-9263 occurs when the system references memory that has been freed, leading to potential exploitation by an attacker.
HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) are affected by CVE-2020-9263.
To fix CVE-2020-9263, update your HUAWEI Mate 30 to version 10.1.0.150(C00E136R5P3) or later and HUAWEI P30 to version 10.1.0.160(C00E160R2P11) or later.