CVE-2022-44549: High severity Huawei Harmonyos vulnerability
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44549?
CVE-2022-44549 is rated as a high-severity vulnerability due to unauthorized access to geofencing APIs.
How do I fix CVE-2022-44549?
To fix CVE-2022-44549, update affected Huawei devices to the latest firmware that addresses this vulnerability.
Which devices are affected by CVE-2022-44549?
CVE-2022-44549 affects Huawei HarmonyOS versions 2.0 and 2.1, as well as EMUI versions 11.0.1, 12.0.0, and 12.0.1.
What impact does CVE-2022-44549 have on user confidentiality?
CVE-2022-44549 can allow third-party apps to access sensitive geofencing APIs without proper authorization, risking user data confidentiality.
Is there an exploit available for CVE-2022-44549?
While specific exploit details are not publicly disclosed, the vulnerability's design flaw inherently permits unauthorized API access.