First published: Thu Jun 03 2021(Updated: )
There is a Business Logic Errors vulnerability in Huawei Smartphone. The malicious apps installed on the device can keep taking screenshots in the background. This issue does not cause system errors, but may cause personal information leakage.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMUI 5.0 | =10.0.0 | |
EMUI 5.0 | =10.1.0 | |
EMUI 5.0 | =10.1.1 | |
EMUI 5.0 | =11.0.0 | |
Magic UI | =3.0.0 | |
Magic UI | =3.1.0 | |
Magic UI | =3.1.1 | |
Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-22308 is categorized as moderate due to the potential for personal information leakage.
To fix CVE-2021-22308, users should update their Huawei devices to the latest available software version provided by Huawei.
CVE-2021-22308 affects Huawei devices running EMUI versions 10.0.0, 10.1.0, 10.1.1, 11.0.0 and Magic UI versions 3.0.0, 3.1.0, 3.1.1, and 4.0.0.
CVE-2021-22308 can be exploited by malicious apps that are already installed on the device to take unauthorized screenshots.
The potential impact of CVE-2021-22308 includes the risk of sensitive personal information being exposed without the user's consent.