First published: Wed Nov 09 2022(Updated: )
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
Credit: psirt@huawei.com psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei HarmonyOS | =2.0 | |
Huawei HarmonyOS | =2.1 | |
Huawei HarmonyOS | =3.0.0 | |
Huawei EMUI | =11.0.1 | |
Huawei EMUI | =12.0.0 | |
Huawei EMUI | =12.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44553 is classified as a security vulnerability that can lead to undesirable behavior of third-party applications.
To fix CVE-2022-44553, users should update their Huawei devices to the latest firmware that addresses this vulnerability.
CVE-2022-44553 affects several Huawei devices running HarmonyOS 2.0, 2.1, and 3.0.0, as well as EMUI versions 11.0.1, 12.0.0, and 12.0.1.
Successful exploitation of CVE-2022-44553 may lead to the unintended activation of third-party applications on the device.
CVE-2022-44553 does not specify remote exploitation; it primarily concerns local app behaviors upon interaction with the HiView module.