First published: Fri Sep 16 2022(Updated: )
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMUI 5.0 | =11.0.0 | |
EMUI 5.0 | =11.0.1 | |
EMUI 5.0 | =12.0.0 | |
HarmonyOS | =2.0 | |
HarmonyOS | =2.1 | |
Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39000 is classified as a high-severity vulnerability due to its potential to allow malicious apps to start automatically upon system startup.
To fix CVE-2022-39000, update your Huawei device to the latest firmware version that addresses this vulnerability.
CVE-2022-39000 affects specific versions of Huawei EMUI 11.0.0, 11.0.1, EMUI 12.0.0, and HarmonyOS 2.0 and 2.1.
Exploitation of CVE-2022-39000 can lead to unauthorized applications being launched automatically, compromising user data and privacy.
Currently, the only reliable workaround for CVE-2022-39000 is to ensure that your device is updated to a version that mitigates the vulnerability.