First published: Wed Oct 11 2023(Updated: )
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.
Credit: psirt@huawei.com psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Harmonyos | =3.0.0 | |
Huawei Harmonyos | =3.1.0 | |
Huawei Harmonyos | =4.0.0 | |
Huawei Emui | =13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41304 is a parameter verification vulnerability in the window module that can cause the size of an app window to be adjusted to that of a floating window.
Huawei HarmonyOS 3.0.0, 3.1.0, 4.0.0, and Huawei EMUI 13.0.0 are affected by CVE-2023-41304.
CVE-2023-41304 has a severity rating of 5.3, which is considered medium.
Exploiting CVE-2023-41304 can be done by manipulating parameters in the window module to adjust the size of an app window to that of a floating window.
To fix CVE-2023-41304, it is recommended to apply the security updates provided by Huawei, as mentioned in their official bulletins.