VYPR
Medium severity4.0NVD Advisory· Published Oct 20, 2025· Updated Apr 15, 2026

CVE-2025-57838

CVE-2025-57838

Description

Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An information leak vulnerability in Honor MagicOS 9.0.0.100 could allow an attacker to compromise service confidentiality.

Vulnerability

Overview

CVE-2025-57838 is an information leak vulnerability affecting certain Honor products running MagicOS 9.0.0.100. The official advisory confirms that successful exploitation may affect service confidentiality [1]. The root cause is not detailed in the public advisory, but the vulnerability is classified as an information disclosure issue.

Exploitation

The advisory does not specify the attack vector, prerequisites, or authentication requirements. However, information leak vulnerabilities typically require local access or a man-in-the-middle position to intercept sensitive data. No proof-of-concept or active exploitation has been publicly reported as of the advisory date.

Impact

An attacker who successfully exploits this vulnerability could gain unauthorized access to confidential information processed by the affected service. This could include user data, system secrets, or other sensitive material, depending on the service's role. The CVSS v3 base score of 4.0 (Medium) reflects the limited scope of the impact, which is confined to confidentiality without affecting integrity or availability.

Mitigation

Honor has released a software update to fix this vulnerability. The fix is included in MagicOS version 9.0.0.100. Users with automatic update prompts for supported products [1]. Users are advised to install the update promptly. No workarounds are provided.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.