Connect with us

HARMONYOS

Huawei publishes April 2024 HarmonyOS security patch details: Check

Published

on

Huawei-HarmonyOS-April-2024-security-patch-details

Well, after the EMUI April 2024 security patch, Huawei is now rolling out the April 2024 HarmonyOS security patch details to compatible device owners. This aims to improve the bug and issue that you encountered or stacked with last month. However, these monthly security fixes details are mentioned based on official HarmonyOS support.

Huawei-HarmonyOS-April-2024-security-patch-details

Notably, it improves your system security and gives it a boost to provide a better user experience. On the other hand, the latest HarmonyOS 4 has already reached out to a number of eligible devices and some of still process with the beta testing. Although, this upcoming monthly update is very necessary for your devices for the security point of view alongside to make it more compatible for major HarmonyOS updates.

Join Telegram Group

As per the info, the Huawei HarmonyOS April 2024 security patch details adds one medium level of CVE from kernal section and 7 medium and 1 high level of CVEs from system section, and 3 medium level from application section. Other than this, it donent resolve any from third party library.

Below you can check the vernarabilities discritop and section of improvement with severity level. For more information join our Telegram group.

Kernal

  • 1 medium level of CVE [CVE-2024-30416]
  • The underlying driver module has a Use After Free (UAF) vulnerability.

System

Medium

  • 7 medium level of CVE [CVE-2024-30418, CVE-2024-30417, CVE-2023-52382, CVE-2023-52714, CVE-2024-30415, CVE-2023-52713, CVE-2024-30413]
  • The Window Manager module has a vulnerability in permission control.
  • The hwnff module has defects introduced in the design process.
  • The notification module has improper control over foreground service notifications.
  • The Bluetooth socket module has a path traversal vulnerability.
  • The application management module has inadequate permission verification.

High

  • 1 high level of CVE [CVE-2024-30414]

Application

  • 3 Medium level of CVE [CVE-2023-52717, CVE-2023-52716, CVE-2023-52715]
  • The SystemUI module has a vulnerability in permission management.
  • The AbilityManagerService (AMS) module has a vulnerability of starting abilities in the background.

None from Third Party Library

Shizuka is a developer, she is the creative mind behind most latest news and update blogs. She likes to listen to classical songs and dance. She used to live a very simple and dedicated life toward animals and poor people, she has her own animal welfare organization in the country.