← Vulnerability feed

Vulnerability record · CVE-2020-9263 · published 19 October 2020

CVE-2020-9263: Huawei mate 30 firmware use after free vulnerability

Huawei · Mate 30 Firmware

HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with common privilege, successful exploit could cause code execution.

7.8 CVSS 3.1 High EPSS 0.83% · top 43.6% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 6.8
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with common privilege, successful exploit could cause code execution.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9263 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0022Google android vulnerabilityIn reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to …EPSS 6.1%8.1CVE-2019-9506Google android broken cryptographic algorithm vulnerabilityThe Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker fr…EPSS 2.7%7.8CVE-2020-9247Huawei honor 20 pro firmware classic buffer overflow vulnerabilityThere is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which …EPSS 0.83%7.8CVE-2020-9262Huawei mate 30 firmware use after free vulnerabilityHUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a use after free vulnerability. There is a condition exists that the system wo…EPSS 0.83%7.8CVE-2020-9261Huawei mate 30 firmware type confusion vulnerabilityHUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a type confusion vulnerability. The system does not properly check and transfo…EPSS 0.79%7.8CVE-2020-1800Huawei p30 firmware vulnerabilityHUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly res…EPSS 0.53%7.8CVE-2020-1812Huawei p30 firmware improper authentication vulnerabilityHUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation…EPSS 0.57%7.8CVE-2019-5225Huawei p30 firmware classic buffer overflow vulnerabilityP30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.1…EPSS 0.83%

Source: NIST National Vulnerability Database (record CVE-2020-9263), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.