CVE-2025-53177Use After Free in Huawei Emui

Severity
3.9LOWNVD
EPSS
0.0%
top 98.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 7

Description

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:LExploitability: 1.3 | Impact: 2.5

Affected Packages4 packages

CVEListV5huawei/emui14.0.0
NVDhuawei/emui14.0.0
CVEListV5huawei/harmonyos4.0.0, 4.2.0, 4.3.0+2
NVDhuawei/harmonyos4.0.0, 4.2.0, 4.3.0+2

🔴Vulnerability Details

2
GHSA
GHSA-w48v-wrf9-w8p7: Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing f2025-07-07
CVEList
CVE-2025-53177: Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing f2025-07-07

📋Vendor Advisories

1
Microsoft
smb: prevent use-after-free due to open_cached_dir error paths2024-12-10
CVE-2025-53177 — Use After Free in Huawei Emui | cvebase