HUAWEI EMUI/Magic UI security updates November 2023
HUAWEI is releasing monthly security updates for flagship models. This security update includes HUAWEI and third-party library patches:
This security update includes the following third-party library patches:
This security update includes the CVE announced in the October 2023 Android security bulletin:
Critical: CVE-2023-4863
High: CVE-2023-40128, CVE-2023-21266, CVE-2023-40121, CVE-2023-40123, CVE-2023-40133, CVE-2023-40134, CVE-2023-40135, CVE-2023-40136, CVE-2023-40137, CVE-2023-40138, CVE-2023-40139, CVE-2023-40140, CVE-2023-40125, CVE-2023-40127, CVE-2023-40130, CVE-2023-33034, CVE-2023-33035, CVE-2023-21394
Medium: none
Low: none
Already included in previous updates: CVE-2023-21281, CVE-2022-20281, CVE-2023-21177
※ For more information on security patches, please refer to the Android security bulletins (https://source.android.com/security/bulletin).
This security update includes the following HUAWEI patches:
CVE-2022-48613: Race condition vulnerability in the kernel module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.0
Impact: Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.
CVE-2023-44098: Vulnerability of missing encryption in the card management module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-44115: Vulnerability of improper permission control in the Booster module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 12.0.0
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-46755: Vulnerability of input parameters being not strictly verified in the input method module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0
Impact: Successful exploitation of this vulnerability may cause the launcher to restart.
CVE-2023-46756: Permission control vulnerability in the window management module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may cause malicious pop-up windows.
CVE-2023-46758: Permission management vulnerability in the multi-screen interaction module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.
CVE-2023-46759: Permission control vulnerability in the call module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-46760: Out-of-bounds write vulnerability in the kernel driver module
Severity: Medium
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability may cause process exceptions.
CVE-2023-46761: Out-of-bounds write vulnerability in the kernel driver module
Severity: Medium
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability may cause process exceptions.
CVE-2023-46762: Out-of-bounds write vulnerability in the kernel driver module
Severity: Medium
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability may cause process exceptions.
CVE-2023-46763: Vulnerability of background app permission management in the framework module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may cause background apps to start maliciously.
CVE-2023-46764: Unauthorized startup vulnerability of background apps
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1 , EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may cause background apps to start maliciously.
CVE-2023-46765: Vulnerability of uncaught exceptions in the NFC module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability can affect NFC availability.
CVE-2023-46766: Out-of-bounds write vulnerability in the kernel driver module
Severity: Medium
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability may cause process exceptions.
CVE-2023-46767: Out-of-bounds write vulnerability in the kernel driver module
Severity: Medium
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability may cause process exceptions.
CVE-2023-46768: Multi-thread vulnerability in the idmap module
Severity: High
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2023-46769: Use-After-Free (UAF) vulnerability in the dubai module
Severity: High
Affected versions: EMUI 13.0.0
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-46770: Out-of-bounds vulnerability in the sensor module
Severity: High
Affected versions: EMUI 13.0.0, EMUI 12.0.0
Impact: Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.
CVE-2023-46771: Security vulnerability in the face unlock module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.0
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-46772: Vulnerability of parameters being out of the value range in the QMI service module
Severity: Medium
Affected versions: EMUI 11.0.1
Impact: Successful exploitation of this vulnerability may cause errors in reading file data.
CVE-2023-46774: Vulnerability of uncaught exceptions in the NFC module
Severity: Medium
Affected versions: EMUI 13.0.0, EMUI 12.0.1, EMUI 12.0.0, EMUI 11.0.1
Impact: Successful exploitation of this vulnerability can affect NFC availability.
CVE-2023-5801: Vulnerability of identity verification being bypassed in the face unlock module
Severity: Critical
Affected versions: EMUI 13.0.0, EMUI 12.0.0
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
- en