CVE-2024-56443

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 8, 2025
Updated: Jan 13, 2025
CWE ID 200

Summary

CVE-2024-56443 is a newly discovered cross-process screen stack vulnerability affecting the UIExtension module. This issue allows an attacker to potentially manipulate the screen stack of another process, threatening service confidentiality. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information or perform unintended actions within the affected system. The full impact of this vulnerability is still under investigation, but it is recommended that affected organizations prioritize deploying patches to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • HarmonyOS

Affected Vendors

  • Huawei Technologies