Huawei EMUI/MagicUI July security update: fix 98 vulnerabilities

Ready, click the button in the top right corner to generate summary
AI thinking...

Huawei is making every effort to update and upgrade the existing equipment of the HarmonyOS Hongmeng system. At the same time, it has not forgotten EMUI and MagicUI, especially in terms of security.

Huawei today issued a security bulletin for July 2021. EMUI Huawei mobile phones and MagicUI glory mobile phones have repaired as many as 98 security vulnerabilities in one go.

Among them, there are 49 Android vulnerabilities, including 21 high-risk levels and 28 medium-level vulnerabilities, and Huawei also has 49 vulnerabilities, including 15 high-risk levels, 26 medium-level vulnerabilities, and 8 low-level vulnerabilities.

The affected system versions include EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, EMUI 10.0.0, EMUI 9.1.1, EMUI 9.1.0, MagicUI 3.1.1, MagicUI 3.1.0, MagicUI 3.0.0, MagicUI 2.1.1.

Supported Huawei and Honor mobile phones will receive security updates this month one after another, and you can pay attention to system update reminders.

Huawei EMUI/MagicUI July security update: fix 98 vulnerabilities

The July 2021 Android security bulletin CVE included in this security update software:

Severe: None

High: CVE-2021-0599, CVE-2020-0417, CVE-2021-0585, CVE-2021-0586, CVE-2021-0587, CVE-2021-0588, CVE-2021-0589, CVE-2021-0590, CVE-2021-0594, CVE-2021-0596, CVE-2021-0597, CVE-2021-0486, CVE-2021-0600, CVE-2021-0601, CVE-2021-0602, CVE-2021-0604, CVE- 2021-0441, CVE-2021-0478, CVE-2021-0512, CVE-2020-11267, CVE-2020-14305

Medium: CVE-2021-0534, CVE-2021-0535, CVE-2021-0537, CVE-2021-0538, CVE-2021-0539, CVE-2021-0541, CVE-2021-0542, CVE-2021-0544, CVE-2021-0545, CVE-2021-0546, CVE-2021-0547, CVE-2021-0548, CVE-2021-0549, CVE-2021-0553, CVE-2021-0555, CVE-2021-0556, CVE- 2021-0557, CVE-2021-0558, CVE-2021-0559, CVE-2021-0561, CVE-2021-0562, CVE-2021-0564, CVE-2021-0567, CVE-2021-0569, CVE-2021- 0570, CVE-2021-0572, CVE-2021-0606, CVE-2021-0605

Low: None

Included in the previous announcement: CVE-2020-0267, CVE-2020-0478, CVE-2021-0489, CVE-2021-0490, CVE-2021-0491, CVE-2021-0492, CVE-2021-0493, CVE -2021-0494, CVE-2021-0495, CVE-2021-0496, CVE-2021-0497, CVE-2021-0498, CVE-2021-0571, CVE-2020-1971, CVE-2021-0563, CVE-2021 -0513, CVE-2021-0368, CVE-2021-0536, CVE-2021-0529, CVE-2021-0530, CVE-2021-0526, CVE-2021-0532, CVE-2021-0533, CVE-2021-0525 , CVE-2021-0527, CVE-2021-0528, CVE-2021-0531

Huawei patches included in this security update software:

CVE-2021-22475: Some Huawei mobile phones have improper rights management vulnerabilities

Severity: low

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22394: Some Huawei products have buffer overflow vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0

Impact: Successfully exploiting this vulnerability can form a Dos attack on multi-screen collaborative applications.

CVE-2021-36997: Some Huawei products trigger low-memory vulnerabilities because they do not limit the image size

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successfully exploiting this vulnerability may cause a library or file management application to crash.

CVE-2021-36996: Some Huawei products have improper verification vulnerabilities

Severity: low

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may lead to partial transmission of virtual information.

CVE-2021-36995: Some Huawei phones have file unauthorized access vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successfully exploiting this vulnerability can tamper with backup and recovery files by modifying the soft link.

CVE-2021-36994: Some Huawei products have security vulnerabilities where the same whitelist string is repeatedly inserted into the linked list due to competition conditions

Severity: low

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability will result in abnormal system whitelist management.

CVE-2021-36993: Some Huawei phones have memory leak vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may affect usability.

CVE-2021-36992: Some Huawei phones have public key verification vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-36991: Some Huawei products have file unauthorized access vulnerabilities due to the failure to standardize the external input path

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability can allow unauthorized access to files by maliciously constructing file paths.

CVE-2021-36990: Some Huawei phones have kernel tampering vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can raise rights.

CVE-2021-36989: Some Huawei phones have kernel Crash vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can raise rights.

CVE-2021-36988: Some Huawei phones have parameter verification issues

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability leads to compromised integrity.

CVE-2021-36987: Some Huawei products have multiple release security vulnerabilities in the same linked list node due to competition conditions

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability will cause the system to restart.

CVE-2021-36986: Some Huawei phones have kernel tampering vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can raise rights.

CVE-2021-36985: Some Huawei products have code injection vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability leads to exhaustion of system resources and system restart.

CVE-2021-22491: Some Huawei products have input verification vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may affect usability.

CVE-2021-22490: Some Huawei phones have permission verification vulnerabilities

Severity: low

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0

Impact: Successful exploitation of this vulnerability may affect the performance of the device.

CVE-2021-22488: Some Huawei phones have file unauthorized access vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successfully exploiting this vulnerability can tamper with backup and recovery files by modifying the soft link.

CVE-2021-22487: Some Huawei phones have out-of-bounds read vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may affect usability.

CVE-2021-22486: Some Huawei mobile phones have field naming non-compliance vulnerabilities

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22485: The ssid vulnerability of all Huawei products connected to WLAN

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22483: Some Huawei phones have forged IP address vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may lead to business denial of service.

CVE-2021-22482: Some Huawei products have variable uninitialized vulnerabilities

Severity: low

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may lead to invalid data transmission.

CVE-2021-36998: Some products have improper verification vulnerabilities

Severity: low

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may lead to the problem of out-of-bounds reading groups.

CVE-2021-22474: Some Huawei phones have out-of-bounds memory access

Severity: Medium

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may lead to abnormal processes.

CVE-2021-22473: Some Huawei products have certification vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, EMUI 10.0.0, EMUI 9.1.1, EMUI 9.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0 , Magic UI 3.0.0, Magic UI 2.1.1

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22472: Some Huawei phones have improper verification vulnerabilities

Severity: high

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22460: Some Huawei mobile phones have bypassed boot restrictions

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22455: An integer overflow vulnerability exists in the Aod driver in some Huawei products

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can escalate root privileges.

CVE-2021-22450: Some Huawei products did not release memory due to abnormal conditions, and there are security vulnerabilities in memory leaks

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability will cause the system memory resources to be exhausted and the phone will restart.

CVE-2021-22436: Some Huawei products have logic bypass vulnerabilities

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may result in compromised integrity and availability.

CVE-2021-22435: Some Huawei products have logic bypass vulnerabilities

Severity: high

Affected version: EMUI 10.1.1, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may result in compromised integrity and availability.

CVE-2021-22425: Some Huawei products have multiple release security vulnerabilities in the same linked list node due to competition conditions

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability will cause the system to restart.

CVE-2021-22423: An integer overflow vulnerability exists in the Aod driver in some Huawei products

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can escalate root privileges.

CVE-2021-22422: An integer overflow vulnerability exists in the Aod driver in some Huawei products

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can escalate root privileges.

CVE-2021-22419: Some Huawei products have vulnerabilities in external apk startup verification

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful exploitation of this vulnerability may cause the counterfeit apk to run automatically.

CVE-2021-22418: An integer overflow vulnerability exists in the Aod driver in some Huawei products

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can escalate root privileges.

CVE-2021-22417: Some Huawei phones have memory leaks and out-of-bounds access

Severity: high

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: Successful use of this vulnerability can escalate root privileges.

CVE-2021-22407: The Huawei Mobile Assistant product has an identity verification vulnerability because it does not verify the identity of the server side when connecting

Severity: low

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22406: Remote DOS vulnerability exists in Changlian app

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, EMUI 10.0.0, EMUI 9.1.1, EMUI 9.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0 , Magic UI 3.0.0, Magic UI 2.1.1

Impact: Successful exploitation of this vulnerability will cause application crashes.

CVE-2021-22405: Some Huawei phones have a configuration flaw vulnerability

Severity: Medium

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may affect usability.

CVE-2021-22404: A directory traversal vulnerability exists in Huawei mobile phones

Severity: low

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, EMUI 10.0.0, EMUI 9.1.1, EMUI 9.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0 , Magic UI 3.0.0, Magic UI 2.1.1

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22403: Some Huawei phones have an unverified Provider hijacking vulnerability

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, EMUI 10.0.0, EMUI 9.1.1, EMUI 9.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0 , Magic UI 3.0.0, Magic UI 2.1.1

Impact: Successfully exploiting this vulnerability will be hijacked by attacking applications, fake interfaces for phishing, and execute malicious commands.

CVE-2021-22402: Some Huawei phones have DOS vulnerabilities

Severity: high

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability leads to a denial of service attack.

CVE-2021-22401: Some Huawei phones have remote DOS vulnerabilities

Severity: high

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability has affected integrity.

CVE-2021-22395: Some Huawei products have code injection vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, EMUI 10.1.0, Magic UI 4.0.0, Magic UI 3.1.1, Magic UI 3.1.0

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-36999: Some Huawei products have buffer overflow vulnerabilities

Severity: Medium

Affected version: EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, Magic UI 3.1.1

Impact: An attacker can exploit this vulnerability by sending a maliciously constructed picture and guiding the user to open it. Successful exploitation of this vulnerability may lead to remote code execution.

CVE-2021-37000: Some Huawei phones have improper rights management vulnerabilities

Severity: high

Affected version: EMUI 11.0.0, Magic UI 4.0.0

Impact: Successful exploitation of this vulnerability may result in compromised confidentiality.

CVE-2021-22367: Some Huawei products have logic bypass vulnerabilities

Severity: high

Affected versions: EMUI 10.1.1, EMUI 10.1.0, EMUI 10.0.0, EMUI 9.1.1, EMUI 9.1.0, Magic UI 3.1.1, Magic UI 3.1.0, Magic UI 3.0.0, Magic UI 2.1. 1

Impact: Successful exploitation of this vulnerability may lead to authentication bypass.

Please indicate the source for reprinting: Fast Technology

.

Previous Article iPad Mini 6 - We are close! (Final Design and Launch)