CVE-2019-5308
Description
Mate 20 RS smartphones with versions earlier than 9.1.0.135(C786E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation in ADB mode, successful exploit could allow the attacker to switch to third desktop after a series of operation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper authorization in ADB mode on Huawei Mate 20 RS allows an attacker to switch to a third-party desktop, bypassing security restrictions.
Vulnerability
An improper authorization vulnerability exists in Huawei Mate 20 RS smartphones running versions earlier than 9.1.0.135(C786E133R3P1) [1]. The software fails to properly restrict certain operations when the device is in Android Debug Bridge (ADB) mode. This allows an attacker to perform actions that should be unauthorized, specifically the ability to switch to a third desktop environment.
Exploitation
To exploit this vulnerability, an attacker must have access to the device while it is in ADB mode, typically requiring a USB connection and ADB debugging enabled. The attacker then executes a series of operations (likely ADB commands) to trigger the unauthorized switch to a third desktop [1]. No authentication is needed beyond the ADB connection, but physical or USB access to the device is required.
Impact
Successful exploitation allows the attacker to switch the device's desktop environment to a third-party launcher or desktop. This could bypass security controls enforced by the default desktop, potentially enabling further unauthorized actions or access to sensitive data. The impact is limited to changing the desktop, but it may serve as a stepping stone for more severe attacks.
Mitigation
Huawei has released a software update to fix this vulnerability. Users should upgrade their Mate 20 RS to version 9.1.0.135(C786E133R3P1) or later [1]. No workarounds are provided in the advisory. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Huawei/Mate 20 RS smartphonesdescription
- Range: <9.1.0.135(C786E133R3P1)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20191127-01-smartphone-enmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.