QID 610453

Date Published: 2022-12-13

QID 610453: Google Android December 2022 Security Patch Missing for Huawei EMUI

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2022-20414, CVE-2022-20441, CVE-2022-20445, CVE-2022-20446, CVE-2022-20448, CVE-2022-20450, CVE-2022-20451, CVE-2022-20453, CVE-2022-20454, CVE-2022-20462, CVE-2022-20463, CVE-2022-20465, CVE-2022-2209, CVE-2022-25724, CVE-2022-25743, CVE-2021-1050, CVE-2022-25741,CVE-2022-20280, CVE-2022-20338

Affected Devices :
HUAWEI Mate series: HUAWEI Mate 40 Pro, HUAWEI Mate 50, HUAWEI Mate 50 Pro, HUAWEI Mate Xs 2, HUAWEI Mate Xs
HUAWEI P series: HUAWEI P40, HUAWEI P40 Pro, HUAWEI P40 Pro+, HUAWEI P50, HUAWEI P50 Pro, HUAWEI P50 Pocket, HUAWEI P50 Pocket Premium Edition, HUAWEI P40 lite 5G
HUAWEI nova series: HUAWEI nova 10, HUAWEI nova 10 Pro, HUAWEI nova 10 SE, HUAWEI nova 9 SE, HUAWEI nova 9, HUAWEI nova 8i, HUAWEI nova 8, HUAWEI nova 7 5G, HUAWEI nova 7 SE 5G, HUAWEI nova 7i
HONOR series: HONOR 30 Pro+, HONOR View30 Pro, HONOR 30, Honor 30S

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to HUAWEI Security advisory December 2022 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    December 2022 Android URL Logo consumer.huawei.com/en/support/bulletin/2022/12