CVE Vulnerabilities

CVE-2022-48296

Improper Preservation of Permissions

Published: Feb 09, 2023 | Modified: Mar 25, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

NameVendorStart VersionEnd Version
EmuiHuawei11.0.1 (including)11.0.1 (including)
EmuiHuawei12.0.0 (including)12.0.0 (including)
EmuiHuawei12.0.1 (including)12.0.1 (including)
HarmonyosHuawei2.0 (including)2.0 (including)
HarmonyosHuawei2.1 (including)2.1 (including)
HarmonyosHuawei3.0.0 (including)3.0.0 (including)

References