VYPR
Unrated severityNVD Advisory· Published May 29, 2020· Updated Aug 4, 2024

CVE-2020-1809

CVE-2020-1809

Description

HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice assistant then do a series of crafted voice operation, successful exploit could allow the attacker read certain files without unlock the phone leading to information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Voice assistant on HUAWEI Mate 10 can be abused to read files without unlocking the device, leaking sensitive information.

Vulnerability

An information disclosure vulnerability exists in HUAWEI Mate 10 smartphones running versions earlier than 10.0.0.143(C00E143R2P4) [1]. The voice assistant can be triggered to execute a series of crafted voice operations, bypassing the lock screen to read certain files [1].

Exploitation

The attacker must have physical access to the locked device and be able to wake the voice assistant with a voice command [1]. No authentication or unlock is needed; the attacker simply issues a series of crafted voice commands to the assistant [1].

Impact

Successful exploitation allows an attacker to read certain files on the device without unlocking it, leading to information disclosure [1]. The scope is local physical access, with no privilege escalation beyond what the voice assistant can access.

Mitigation

Huawei released software update 10.0.0.143(C00E143R2P4) to fix this vulnerability [1]. Users should update their devices to the latest version. No workaround is mentioned in the advisory [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.