CVE-2022-48289: Huawei Emui

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

Affected products

  • Huawei Emui: version 12.0.1 only
  • Huawei Harmonyos: version 2.0.1 only; version 3.0.0 only

Published 2023-02-09. Last modified 2026-06-17.