Connect with us

EMUI

Huawei June 2022 update fixes EMUI 12 feature issue

Published

on

huawei june 2022 emui 12 feature issue

Huawei has recently published June 2022 EMUI security patch details. June 2022 bulletin mentioned a bunch of EMUI security flaws that have been fixed but there’s one specific Huawei EMUI 12 feature issue that we want to mention here.

Huawei EMUI June 2022 security patch fixes EMUI 12 multi-device task center feature issue, the exploitation of this feature could allow attacks to compromise your device’s data. However, it’s fixed with the upcoming firmware version and patched with June 2022 security patch.

Multi-Task Center:

This feature is powered by Huawei’s cross-device capabilities used in EMUI devices that allow you to get the most out of the software. Based on the concept of multi-device collaboration, the feature allows you to project application data from one device to another in real-time, check the example below.

huawei june 2022 emui 12 feature issue

For instance, if you are running a game on your smartphone, you just need to go to the task manager of the phone and task manager view. Now, tap on the device (such as a tablet) to run the corresponding app. However, the user must first need to connect the tablet and the phone via the same WiFi network and Huawei ID.

Advertisement

Similarly, another task can also be handled by the task center such as viewing documents on a tablet for a bigger view, without even installing any additional app.

Check all of the issues that are mentioned in the June 2022 EMUI security patch.

CVE-2021-46812: Device manager vulnerability in the multi-device task center

Severity: Medium

Advertisement

Affected versions: EMUI 12.0.0

Impact: Successful exploitation of this vulnerability can affect integrity.

CVE-2021-46811: Improper permission management vulnerability in the HwSEServiceAPP module

Severity: High

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may lead to the acquisition of CPLC information.

CVE-2021-40021: Out-of-bounds memory write in the eID module

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2021-40022: Missing parameter type validation in the weaver module

Severity: Critical

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2021-40014: Information management error vulnerability in the bone voice ID TA

Severity: High

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2021-40006: Security risk of brute force cracking in the fingerprint sensor module

Severity: High

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may affect confidentiality.

CVE-2022-31751: Multi-thread competition for resources in the kernel emcom module

Severity: Critical

Advertisement

Affected versions: EMUI 10.0.0, EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, Magic UI 3.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31757: Interface misuse vulnerability in the Settings module

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2022-31763: Null pointer and out-of-bounds array vulnerabilities in the kernel module

Severity: High

Advertisement

Affected versions: EMUI 12.0.0

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31760: Dialog box being displayed when the screen is locked in the carrier-customized USSD service

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

CVE-2022-31758: Race condition vulnerability in the kernel module

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2021-46814: Out-of-bounds memory read and write vulnerability in the video framework

Severity: High

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31753: Vulnerability of using externally-controlled format strings in the voice wakeup module

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31754: Logical defects in code implementation in some products

Severity: Medium

Advertisement

Affected versions: EMUI 12.0.0, EMUI 10.1.0, Magic UI 3.1.0

Impact: Successful exploitation of this vulnerability may affect the availability of some features.

CVE-2021-46813: Vulnerability of residual files not being deleted after an update in the ChinaDRM module

Severity: Critical

Advertisement

Affected versions: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2021-46815: Configuration defects in the secure OS module

Severity: Medium

Advertisement

Affected versions: EMUI 10.0.0, EMUI 10.1.0, EMUI 10.1.1, EMUI 12.0.0, Magic UI 3.0.0, Magic UI 3.1.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31761: Configuration defects in the secure OS module

Severity: High

Advertisement

Affected versions: EMUI 10.1.1, EMUI 11.0.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2022-29793: Configuration defects in the activation lock of the mobile phone

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, Magic UI 3.1.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may affect availability.

CVE-2022-31755: Improper preservation of permissions vulnerability in the communications module

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31759: Uninitialized pointer access vulnerability in the AppLink

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability can affect availability.

CVE-2022-31762: Input verification vulnerability in the AMS module

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will cause unauthorized operations.

CVE-2022-31752: Missing authorization vulnerability in the system components

Severity: Medium

Advertisement

Affected versions: EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, EMUI 11.0.1, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

CVE-2022-31756: Design defects in the fingerprint sensor module

Severity: High

Advertisement

Affected versions: EMUI 10.0.0, EMUI 10.1.0, EMUI 10.1.1, EMUI 11.0.0, EMUI 12.0.0, Magic UI 3.0.0, Magic UI 3.1.0, Magic UI 3.1.1, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability will affect confidentiality.

Most of Deng Li's smartphones are from the Huawei ecosystem and his first Huawei phone was Ascend Mate 2 (4G). As a tech enthusiast, he keeps exploring new technologies and inspects them closely. Apart from the technology world, he takes care of his garden.

EMUI

Huawei Nova Y90 and Y70 grabs January 2023 EMUI update

Published

on

Huawei Nova Y90

Huawei has released the January 2023 software update for the Huawei Nova Y90 and Y70 smartphones in the global market, and this firmware clearly improves these phones’ security aspects for a better user experience.

Both Huawei Nova Y90 and Y70 runs EMUI 12 out of the box but it would be interesting if the company could have sent EMUI 13 instead of the security patch. Speaking of which, no one knows, when Huawei will rollout EMUI 13 for global users for the time being.

Coming back to the rollout, January 2023 security update for Huawei Nova Y90 and Nova Y70 comes with EMUI version 12.0.1.177 and EMUI 12.0.1.202. This update is suggested to install on all of the devices sold marketed outside of China and will appear in batches.

We suggest the corresponding users look into the settings > then open System & updates, followed by a Software update, and then tap on CHECK FOR UPDATES.  You can download the latest firmware also from the My Huawei app.

Advertisement

You should know that the update won’t erase your personal data but it is suggested for you back up any important data before updating the device. On the other hand, the package will be deleted automatically once the installation succeeds.

Thanks to the tipster for this amazing information, Masterpiece.

Huawei Nova Y90 January 2023 update

(via)

Advertisement
Continue Reading

EMUI

Check February 2023 EMUI security patch details

Published

on

By

Huawei EMUI February 2023 security patch

Huawei has released February 2023 EMUI security patch details that will fetch better safety for smartphones running EMUI 12.0.1, EMUI 12.0, and EMUI 11 in the global market.

In the meantime, Huawei keeps on sending security patches, optimizations, and other important performance upgrades over the OTA method directly to the devices.

Meanwhile, Huawei has not released the February 2023 EMUI security patch update for smartphones but it may soon be delivered to the corresponding eligible models.

Why it’s important?

Security patches are important and Huawei releases such upgrades for smartphones to implement high safety measures to guard the data and fight vulnerabilities. Such updates roll out monthly and quarterly sessions.

Advertisement

What fixed:

Huawei has fixed 2 issues in critical condition, 14 of them fixed in high mode, medium and low level of vulnerabilities are not recorded this time. While there are 23 common vulnerability exposures patched from the last firmware version.

Specifically, it fixes an unauthorized access vulnerability (CVE-2022-48286) in the multi-screen collaboration module, which could have affected the confidentiality of the files that you are sharing over the air.

There are two medium-level vulnerabilities fixed for Bluetooth modules, which could exploit user data. CVE-2022-48295 addresses the fix of authentification of the IHwAntiMalPlugin API, which could let malware attack your Huawei device.

Next comes the Huawei fix for permission management vulnerability in the SystemUI module, which may cause users to receive misleading broadcasts from malicious apps for storage exploitations.

Advertisement

Below you can check all of the CVE counts and codes mentioned in the February 2023 security bulletin.

Critical:

  • CVE-2022-22088, CVE-2022-41674

High:

  • CVE-2022-20456, CVE-2022-20461, CVE-2022-20489, CVE-2022-20490, CVE-2022-20492, CVE-2022-20493, CVE-2022-20494, CVE-2023-20905, CVE-2023-20913, CVE-2023-20915, CVE-2023-20920, CVE-2023-20921, CVE-2022-33255, CVE-2022-32635

Already included in previous updates:

  • CVE-2022-20504, CVE-2022-20506, CVE-2022-20513, CVE-2022-20515, CVE-2022-20516, CVE-2022-20517, CVE-2022-20518, CVE-2022-20520, CVE-2022-20521, CVE-2022-20525, CVE-2022-20528, CVE-2022-20530, CVE-2022-20537, CVE-2022-20539, CVE-2022-20541, CVE-2022-20544, CVE-2022-20546, CVE-2022-20552, CVE-2022-42535, CVE-2022-42542, CVE-2022-20496, CVE-2022-20566, CVE-2021-39793

February 2023 security patch may take some time to toss over the devices and we’ll keep you posted.

Huawei EMUI February 2023 security patch

Continue Reading

EMUI

Huawei Nova 7 January 2023 EMUI update is expanding

Published

on

Huawei Nova 7

Huawei is expanding the January 2023 security patch for Nova 7 global version that improves the phone’s capability against potential threats. According to the information, Huawei Nova 7 January 2023 EMUI update comes with version 12.0.0.244 and 233 megabytes. This update is rolling out in batches began to rollout early last month.

You can check for the update via Settings or via the My Huawei app. Below you can see the update changelog:

This update improves system security with security patches.

Security:

Advertisement
  1. Integrates security patches released in January 2023 for improved system security.

Update notes:

  1. This update will not erase your personal data but we recommend that you back up only important data before updating.
  2. If you encounter any issues during the update contact the Huawei customer service hotline.
  3. The update package will be deleted automatically after the update is complete.

Thanks to the tipster – Mohammed for this amazing update.

Huawei Nova 7 January 2023 update

Continue Reading