CVE-2018-7932: Huawei Appgallery

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

Affected products

  • Huawei Appgallery: before 8.0.4.301 (fixed in 8.0.4.301)

Published 2018-04-24. Last modified 2026-06-17.