Information disclosure in Huawei products - CVE-2019-5264
Published: December 16, 2019
Vulnerability details
The vulnerability allows an attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected software does not properly handle certain information of application locked by applock in a rare condition. An attacker with physical access to the device can gain unauthorized access to sensitive information on the system.
Affected software
Huawei Mate 10 Pro
Huawei Honor V10
Changxiang 7S
Huawei P-smart
Changxiang 8 Plus
Huawei Y9 2018
Huawei Honor 9 Lite
Huawei Honor 9i
Huawei Mate 9
How to mitigate CVE-2019-5264
Huawei Mate 10 Pro - addressed in versions 9.0.0.159, 9.0.0.161, 9.0.0.167
Huawei Honor V10 - addressed in versions 9.0.0.156, 9.0.0.159
Changxiang 7S - update to 9.1.0.107
Huawei P-smart - addressed in versions 9.1.0.119, 9.1.0.130
Changxiang 8 Plus - update to 9.1.0.111
Huawei Y9 2018 - addressed in versions 9.1.0.115, 9.1.0.120
Huawei Honor 9 Lite - addressed in versions 9.1.0.113, 9.1.0.118, 9.1.0.121
Huawei Honor 9i - addressed in versions 9.1.0.106, 9.1.0.112
Huawei Mate 9 - addressed in versions 9.0.1.158, 9.0.1.159