UIExtension module Vulnerability May Affect Service Confidentiality
CVE-2024-54110

6.2MEDIUM

Key Information:

Vendor

Huawei

Status
Vendor
CVE Published:
12 December 2024

What is CVE-2024-54110?

A cross-process screen stack vulnerability has been identified in the UIExtension module developed by Huawei. This flaw allows for the potential unauthorized access to sensitive service information, compromising the confidentiality of user data. Exploitation of this vulnerability could lead to significant privacy risks for users relying on affected versions of the UIExtension module. Users and administrators are advised to review the security bulletins and apply recommended patches to secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HarmonyOS 5.0.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.