CVE-2022-48496

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 19, 2023
Updated: Dec 17, 2024
CWE ID 306
CWE ID 287

Summary

CVE-2022-48496 refers to a vulnerability that allows malicious apps to bypass proper identity verification during the pre-authorization process. This lax identity verification can result in unauthorized apps being granted pre-authorization, posing a significant risk to security. The vulnerability could be exploited to gain unapproved access to sensitive information or functionality. Attackers could potentially install malware or perform other malicious activities. Organizations are strongly advised to update their systems to address this issue and enforce strict app identity verification measures to prevent unauthorized pre-authorization.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Huawei EMUI

Affected Vendors

  • Huawei Technologies