This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy

Security Notice-Statement on the Wooyun-disclosed XSS Vulnerability in Huawei Smartphone Browser

  • Initial Release Date: May 29, 2015
  • Last Release Date: May 29, 2015


Huawei noticed that on May 28, 2015, Wooyun disclosed information on its website about the cross-site scripting (XSS) vulnerability in the built-in Chrome browser of Huawei smartphones. Huawei has completed the analysis and investigation on this vulnerability.

It is confirmed that this vulnerability is an original vulnerability (CVE-2012-2886) in earlier Android versions, and Huawei products affected by this vulnerability are no longer produced. Huawei smartphones using later Android versions do not have this vulnerability.

2015-05-29 INITIAL

Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism. Please report to Huawei PSIRT at psirt@huawei.com if you find any security vulnerability of Huawei products.

Please refer to the following links:

http://www.wooyun.org/bugs/wooyun-2010-098187/

https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2886