You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HMS Push Kit安全漏洞问题咨询及修复方案确认

HMS Push Kit 安全漏洞解决方案

版本修复说明

你反馈的HmsMsgService无权限限制导致的CWE-925、MSTG-PLATFORM-1违规问题,官方已在HMS Push Kit 5.3.0.304及更高版本完成修复,调整了服务的权限校验逻辑,默认阻断第三方应用的非法访问,升级后无需额外配置即可解决该安全风险。

低版本临时规避方案

如果当前业务暂时无法升级SDK版本,可通过Android清单合并规则覆盖SDK的默认服务配置,手动添加签名级权限限制:

  1. 在应用AndroidManifest.xml的根节点下自定义签名级权限:
<permission
    android:name="${applicationId}.PUSH_SERVICE_PERMISSION"
    android:protectionLevel="signature" />
  1. 重新声明HmsMsgService,覆盖SDK的默认配置,添加权限校验:
<service
    android:name="com.huawei.hms.support.api.push.service.HmsMsgService"
    android:enabled="true"
    android:exported="true"
    android:permission="${applicationId}.PUSH_SERVICE_PERMISSION"
    android:process=":pushservice"
    android:directBootAware="true"
    tools:replace="android:permission">
    <intent-filter>
        <action android:name="com.huawei.push.msg.NOTIFY_MSG" />
        <action android:name="com.huawei.push.msg.PASSBY_MSG" />
    </intent-filter>
</service>

注意:需要在manifest根节点添加xmlns:tools="http://schemas.android.com/tools"声明,才能正常使用tools:replace属性覆盖SDK配置。

适配说明

  • 上述自定义配置不会影响Push Kit的正常消息接收功能,HMS Core系统服务调用该接口时符合签名校验规则,可正常访问
  • 优先选择升级官方修复后的SDK版本,经过全量兼容性验证,无需额外适配即可解决问题

内容的提问来源于stack exchange,提问作者0405aj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 01:06:05