First published: Mon Jun 19 2023(Updated: )
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
Credit: psirt@huawei.com psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei EMUI | =11.0.1 | |
Huawei EMUI | =12.0.0 | |
Huawei EMUI | =12.0.1 | |
Huawei EMUI | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48496 has been classified as a high-severity vulnerability due to the potential for malicious app pre-authorization.
To fix CVE-2022-48496, update your Huawei EMUI software to the latest version provided by the manufacturer.
CVE-2022-48496 affects Huawei EMUI versions 11.0.1, 12.0.0, 12.0.1, and 13.0.0.
CVE-2022-48496 allows attackers to achieve pre-authorization of malicious applications, potentially compromising user data.
Currently, there are no known workarounds for CVE-2022-48496; updating to a patched version is the recommended approach.