CVE-2022-48518: Huawei Emui
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
Affected products
- Huawei Emui: version 12.0.0 only; version 12.0.1 only
- Huawei Harmonyos: version 2.0.0 only; version 2.0.1 only
Published 2023-07-06. Last modified 2026-06-17.