Security Bulletins for HUAWEI Phones/Tablets, March 2025
HUAWEI is releasing monthly security updates for flagship models. This security update includes HUAWEI and third-party library patches:
This security update includes the following HUAWEI patches:
CVE | Vulnerability Description | Impact | Severity | Affected Version |
---|---|---|---|---|
CVE-2024-58043 | Permission bypass vulnerability in the window module | Successful exploitation of this vulnerability may affect service confidentiality. | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.0.0, HarmonyOS3.1.0, HarmonyOS2.0.0, HarmonyOS2.1.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-58044 | Permission verification bypass vulnerability in the notification module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.0.0, HarmonyOS3.1.0, HarmonyOS2.0.0, HarmonyOS2.1.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2025-27521 | Vulnerability of improper access permission in the process management module | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS5.0.0 |
CVE-2024-58045 | Multi-concurrency vulnerability in the media digital copyright protection module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS5.0.0 |
CVE-2024-58046 | Permission management vulnerability in the lock screen module | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS5.0.0 |
CVE-2024-58047 | Permission verification vulnerability in the media library module | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS5.0.0 |
CVE-2024-58048 | Multi-thread problem vulnerability in the package management module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS5.0.0 |
CVE-2024-58049 | Permission verification vulnerability in the media library module | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS5.0.0 |
CVE-2024-58050 | Vulnerability of improper access permission in the HDC module | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS5.0.0 |
This security update includes the following third-party library patches:
CVE | Severity | Affected Version |
---|---|---|
CVE-2024-49721 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.1.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-49743 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.1.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2025-0100 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.1.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2025-0091 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2025-0094 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, EMUI 14.0.0, EMUI 13.0.0 |
CVE-2024-49729 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, EMUI 14.0.0, EMUI 13.0.0 |
CVE-2024-49833 | High | HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, EMUI 14.0.0, EMUI 13.0.0 |
CVE-2024-49834 | High | HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-53104 | High | HarmonyOS5.0.0, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-49744 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.1.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-49724 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.1.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-43765 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.1.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-43083 | High | HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, HarmonyOS3.1.0, HarmonyOS3.0.0, HarmonyOS2.0.0, EMUI 14.0.0, EMUI 13.0.0, EMUI 12.0.0 |
CVE-2024-56615 | High | HarmonyOS5.0.0 |
CVE-2024-56587 | Medium | HarmonyOS5.0.0 |
CVE-2024-56670 | Medium | HarmonyOS5.0.0 |
CVE-2025-0587 | Low | HarmonyOS5.0.0 |
CVE-2025-20021 | Low | HarmonyOS5.0.0 |
CVE-2025-20024 | Low | HarmonyOS5.0.0 |
CVE-2025-20626 | Low | HarmonyOS5.0.0 |
CVE-2025-21084 | Low | HarmonyOS5.0.0 |
CVE-2025-21089 | Low | HarmonyOS5.0.0 |
CVE-2025-21097 | Low | HarmonyOS5.0.0 |
CVE-2025-22443 | Low | HarmonyOS5.0.0 |
CVE-2025-22837 | Low | HarmonyOS5.0.0 |
CVE-2025-22841 | Low | HarmonyOS5.0.0 |
CVE-2025-22847 | Low | HarmonyOS5.0.0 |
CVE-2025-22897 | Low | HarmonyOS5.0.0 |
CVE-2025-23234 | Low | HarmonyOS5.0.0 |
CVE-2025-23240 | Low | HarmonyOS5.0.0 |
CVE-2025-23414 | Low | HarmonyOS5.0.0 |
CVE-2025-23418 | Low | HarmonyOS5.0.0 |
CVE-2025-23420 | Low | HarmonyOS5.0.0 |
CVE-2025-24301 | Low | HarmonyOS5.0.0 |
CVE-2025-24309 | Low | HarmonyOS5.0.0 |
CVE-2025-20011 | Low | HarmonyOS5.0.0 |
CVE-2025-20081 | Low | HarmonyOS5.0.0 |
CVE-2025-20091 | Low | HarmonyOS5.0.0 |
CVE-2025-23409 | Low | HarmonyOS5.0.0 |
CVE-2024-53099 | Low | HarmonyOS5.0.0 |
CVE-2024-50304 | Low | HarmonyOS5.0.0 |
Updated on: 2025-03-05
- en