Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42035 | Hig | 0.55 | 8.4 | 0.00 | Aug 8, 2024 | Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality. | ||
| CVE-2024-39672 | Hig | 0.55 | 8.4 | 0.00 | Jul 25, 2024 | Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability. | ||
| CVE-2024-32997 | Hig | 0.55 | 8.4 | 0.00 | May 14, 2024 | Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2021-22376 | Hig | 0.55 | 8.4 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions. | ||
| CVE-2025-54622 | Hig | 0.54 | 8.3 | 0.00 | Aug 6, 2025 | Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54655 | Hig | 0.53 | 8.1 | 0.00 | Aug 6, 2025 | Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module. | ||
| CVE-2025-48911 | Hig | 0.53 | 8.2 | 0.00 | Jun 6, 2025 | Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-48905 | Hig | 0.53 | 8.1 | 0.00 | Jun 6, 2025 | Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types. | ||
| CVE-2024-51526 | Hig | 0.53 | 8.2 | 0.00 | Nov 5, 2024 | Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-34154 | Hig | 0.53 | 8.2 | 0.00 | Jun 16, 2023 | Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources. | ||
| CVE-2021-37134 | Hig | 0.53 | 8.1 | 0.00 | Jan 3, 2022 | Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components. | ||
| CVE-2021-37074 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2021 | There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation. | ||
| CVE-2025-68958 | Hig | 0.52 | 8.0 | 0.00 | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-68956 | Hig | 0.52 | 8.0 | 0.00 | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-68955 | Hig | 0.52 | 8.0 | 0.00 | Jan 14, 2026 | Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58310 | Hig | 0.52 | 8.0 | 0.00 | Nov 28, 2025 | Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54634 | Hig | 0.52 | 8.0 | 0.00 | Aug 6, 2025 | Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-68968 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2026 | Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function. | ||
| CVE-2025-58287 | Hig | 0.51 | 7.8 | 0.00 | Oct 11, 2025 | Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-48903 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2025 | Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability. |
- risk 0.55cvss 8.4epss 0.00
Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.
- risk 0.55cvss 8.4epss 0.00
Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
- risk 0.55cvss 8.4epss 0.00
Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.55cvss 8.4epss 0.00
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
- risk 0.54cvss 8.3epss 0.00
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.53cvss 8.1epss 0.00
Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.
- risk 0.53cvss 8.2epss 0.00
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.53cvss 8.1epss 0.00
Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types.
- risk 0.53cvss 8.2epss 0.00
Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.53cvss 8.2epss 0.00
Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.
- risk 0.53cvss 8.1epss 0.00
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
- risk 0.53cvss 8.1epss 0.01
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.
- risk 0.52cvss 8.0epss 0.00
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.52cvss 8.0epss 0.00
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.52cvss 8.0epss 0.00
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.52cvss 8.0epss 0.00
Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.52cvss 8.0epss 0.00
Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.51cvss 7.8epss 0.00
Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.
- risk 0.51cvss 7.8epss 0.00
Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.51cvss 7.8epss 0.00
Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.
Page 9 of 54