CVE-2023-34165: Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause...

Description

Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.

Classification

CVE ID: CVE-2023-34165

Affected Products

Vendor: Huawei

Product: HarmonyOS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.08% (probability of being exploited)

EPSS Percentile: 36.78% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://device.harmonyos.com/en/docs/security/update/security-bulletins-202306-0000001560777672

Timeline