CVE-2019-5305 describes a memory double free vulnerability in the image processing module of specific Huawei Mate 10 smartphones running firmware versions prior to ALP-L29 9.0.0.159(C185). An attacker can exploit this by tricking a user into installing a malicious application, which then calls a special API to trigger the double free, leading to a system crash. Rated Medium with a CVSS score of 5.5, this vulnerability requires user interaction (UI:R) and local access (AV:L), but has low attack complexity (AC:L). The primary impact is a high availability loss (A:H), meaning the device could become unusable. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting low public awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< alp-l29_9.0.0.159\(c185\)CPE matchmatch criteria | cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.