CVE-2021-37091

7.5 HIGH

📋 TL;DR

This CVE describes a permissions, privileges, and access controls vulnerability in Huawei smartphones running HarmonyOS. Successful exploitation could allow unauthorized access to sensitive information, affecting confidentiality. Users of affected Huawei devices are at risk.

💻 Affected Systems

Products:
  • Huawei smartphones running HarmonyOS
Versions: HarmonyOS 2.0 versions before 2.0.0.230
Operating Systems: HarmonyOS
Default Config Vulnerable: ⚠️ Yes
Notes: Affects devices running vulnerable HarmonyOS versions. Requires malicious app installation or physical access to exploit.

📦 What is this software?

⚠️ Risk & Real-World Impact

🔴

Worst Case

An attacker could gain unauthorized access to sensitive user data stored on the device, potentially including personal information, authentication tokens, or app data.

🟠

Likely Case

Local privilege escalation allowing malicious apps to access data they shouldn't have permission to view.

🟢

If Mitigated

With proper app sandboxing and security updates, the impact is limited to isolated app data rather than system-wide compromise.

🌐 Internet-Facing: LOW (This appears to be a local vulnerability requiring app installation or physical access)
🏢 Internal Only: MEDIUM (Malicious apps could exploit this if installed on corporate devices)

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ✅ No
Complexity: MEDIUM

Exploitation likely requires malicious app installation or physical device access. No public exploit code is known.

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: HarmonyOS 2.0.0.230 and later

Vendor Advisory: https://device.harmonyos.com/en/docs/security/update/security-bulletins-202109-0000001196270727

Restart Required: Yes

Instructions:

1. Go to Settings > System & updates > Software update. 2. Check for updates. 3. Install HarmonyOS 2.0.0.230 or later. 4. Restart device when prompted.

🔧 Temporary Workarounds

Restrict app installations

all

Only install apps from trusted sources like Huawei AppGallery

Settings > Security > Install unknown apps > Disable for all apps

Enable enhanced security features

all

Turn on additional security protections in HarmonyOS

Settings > Security > More security settings > Enable all available protections

🧯 If You Can't Patch

  • Isolate affected devices from sensitive networks and data
  • Implement mobile device management (MDM) with strict app whitelisting

🔍 How to Verify

Check if Vulnerable:

Check HarmonyOS version in Settings > About phone > HarmonyOS version

Check Version:

Settings > About phone > HarmonyOS version

Verify Fix Applied:

Verify HarmonyOS version is 2.0.0.230 or higher

📡 Detection & Monitoring

Log Indicators:

  • Unusual permission requests from apps
  • Failed permission elevation attempts

Network Indicators:

  • Unusual data exfiltration from mobile devices

SIEM Query:

Look for HarmonyOS security logs indicating permission violations or unusual app behavior

🔗 References

📤 Share & Export