First published: Thu Oct 28 2021(Updated: )
There is a vulnerability of hijacking unverified providers in Huawei Smartphone.Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei EMUI | =9.1.0 | |
Huawei EMUI | =9.1.1 | |
Huawei EMUI | =10.0.0 | |
Huawei EMUI | =10.1.0 | |
Huawei EMUI | =10.1.1 | |
Huawei EMUI | =11.0.0 | |
Huawei Magic UI | =2.1.1 | |
Huawei Magic UI | =3.0.0 | |
Huawei Magic UI | =3.1.0 | |
Huawei Magic UI | =3.1.1 | |
Huawei Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-22403 is classified as high due to the potential for device hijacking and user manipulation.
To fix CVE-2021-22403, users should update their Huawei devices to the latest software version provided by Huawei.
CVE-2021-22403 affects Huawei devices running EMUI versions 9.1.0, 9.1.1, 10.0.0, 10.1.0, 10.1.1, and 11.0.0, as well as Magic UI versions 2.1.1, 3.0.0, 3.1.0, 3.1.1, and 4.0.0.
If CVE-2021-22403 is not patched, attackers may hijack your device, allowing them to forge user interfaces and execute malicious commands.
CVE-2021-22403 was discovered in July 2021, highlighting vulnerabilities in Huawei smartphones.