CVE-2017-8165
Description
Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation may cause sensitive information leak.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Sensitive information leak in Huawei Mate 9 CMA implementation via malicious app; fixed in MHA-AL00BC00B233.
Vulnerability
The vulnerability resides in the CMA (Ciphertext Message Authentication) implementation of Huawei Mate 9 smartphones running versions earlier than MHA-AL00BC00B233. An attacker can trick a user into installing a malicious application, which then exploits this flaw to leak sensitive information from the device. No special configuration or additional privileges beyond the malicious app installation are required for the vulnerable code path to be reachable.
Exploitation
An attacker must craft a malicious application and convince the user to install it on the affected device. Once installed, the application interacts with the vulnerable CMA component, leading to the leakage of sensitive information. No further user interaction or network position is needed after installation.
Impact
Successful exploitation results in the disclosure of sensitive information stored on the device. The exact type of information (e.g., credentials, personal data) is not detailed in the advisory, but the leak compromises confidentiality. No code execution or privilege escalation is described.
Mitigation
Huawei has released software update MHA-AL00BC00B233 to fix this vulnerability. The update is available via the vendor's normal update channels. No workarounds are documented. The vulnerability is not listed on the CISA KEV as of the publication date. For more details, see Huawei's security advisory [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Huawei Technologies Co., Ltd./Mate 9v5Range: Versions earlier than MHA-AL00BC00B233
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20171117-01-smartphone-enmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.