CVE-2020-9081
Description
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An improper authorization vulnerability in Huawei smartphones allows an attacker to bypass the app lock via a series of operations in a specific mode on affected models.
Vulnerability
An improper authorization vulnerability exists in Huawei smartphones, specifically in the app lock functionality. The affected models include HUAWEI Mate 20 (versions earlier than 10.1.0.160(C00E160R3P8) and earlier than 10.1.0.160(C01E160R2P8)) and HUAWEI P30 (versions earlier than 10.1.0.160(C00E160R2P11)), as well as potentially other models listed in the vendor advisory [1]. The vulnerability is triggered when an attacker performs a series of operations in a specific mode, exploiting insufficient authorization checks to bypass the application lock screen.
Exploitation
An attacker needs physical access to the unlocked device or the ability to enter the specific mode (e.g., emergency call or recovery mode). The attacker then executes a sequence of steps (not fully detailed in the public advisory) that leverage the improper authorization to circumvent the app lock mechanism. No additional authentication, network access, or user interaction beyond initial device access is required [1].
Impact
Successful exploitation allows the attacker to bypass the app lock, thereby gaining unauthorized access to protected applications on the device. This leads to potential disclosure of private data (e.g., messages, photos, financial apps) and violates the intended confidentiality protection of the device. The attacker does not gain system-level privileges, but the app lock bypass undermines user privacy [1].
Mitigation
Huawei released software updates to fix this vulnerability on 2020-08-26. Affected users should upgrade to the resolved versions: HUAWEI Mate 20 to 10.1.0.160(C00E160R3P8) or 10.1.0.160(C01E160R2P8); HUAWEI P30 to 10.1.0.160(C00E160R2P11). The full list of affected products and corresponding patches is available in the vendor security advisory [1]. No workaround is provided; patching is the only mitigation.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- Range: Versions earlier than 10.1.0.160(C00E160R3P8)
- Range: Versions earlier than 10.1.0.160(C00E160R2P11)
- Range: Versions earlier than 10.1.0.160(C00E160R2P8)
- Huawei/Princeton-AL10Dv5Range: Versions earlier than 10.1.0.160(C00E160R2P11)
- Huawei/Yale-AL00Av5Range: Versions earlier than 10.1.0.160(C00E160R8P12)
- Huawei/Yale-AL50Av5Range: Versions earlier than 10.1.0.88(C00E88R8P1)
- Huawei/YaleP-AL10Bv5Range: Versions earlier than 10.1.0.160(C00E160R8P12)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.