VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2021-46785
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
Published 2022-05-13 · Modified
5.3EPSS 0.005
CVE-2021-37132
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
Published 2022-01-03 · Modified
5.3EPSS 0.005
CVE-2021-46811
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
Published 2022-06-13 · Modified
5.3EPSS 0.005
CVE-2021-37112
Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability may lead to Firmware leak.
Published 2022-01-03 · Modified
5.3EPSS 0.005
CVE-2021-37058
There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user's nickname is maliciously tampered with.
Published 2021-12-07 · Modified
5.3EPSS 0.005
CVE-2021-39981
Chang Lian application has a vulnerability which can be maliciously exploited to hide the calling number.Successful exploitation of this vulnerability allows you to make an anonymous call.
Published 2022-01-03 · Modified
5.3EPSS 0.005
CVE-2023-41312
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
Published 2023-09-26 · Modified
5.3EPSS 0.004
CVE-2022-46313
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.
Published 2022-12-20 · Modified
5.3EPSS 0.004
CVE-2023-6273
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-12-06 · Modified
5.3EPSS 0.004
CVE-2023-46755
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
Published 2023-11-08 · Modified
5.3EPSS 0.004
CVE-2022-48361
The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources.
Published 2023-03-27 · Modified
5.3EPSS 0.004
CVE-2023-41311
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
Published 2023-09-26 · Modified
5.3EPSS 0.004
CVE-2023-44102
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
Published 2023-10-11 · Modified
5.3EPSS 0.004
CVE-2023-52112
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2024-01-16 · Modified
5.3EPSS 0.003
CVE-2022-44553
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
Published 2022-11-09 · Modified
5.3EPSS 0.003
CVE-2023-44094
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
Published 2023-10-11 · Modified
5.3EPSS 0.003
CVE-2023-46763
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.
Published 2023-11-08 · Modified
5.3EPSS 0.003
CVE-2023-46764
Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.
Published 2023-11-08 · Modified
5.3EPSS 0.003
CVE-2023-3456
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-07-06 · Modified
5.3EPSS 0.003
CVE-2022-44560
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.
Published 2022-11-09 · Modified
5.3EPSS 0.003
CVE-2023-46756
Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
Published 2023-11-08 · Modified
5.3EPSS 0.003
CVE-2022-46318
The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings.
Published 2022-12-20 · Modified
5.3EPSS 0.003
CVE-2023-37238
Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
Published 2023-07-06 · Modified
5.3EPSS 0.003
CVE-2023-39387
Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
Published 2023-08-13 · Modified
5.3EPSS 0.003
CVE-2024-56445
Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-01-08 · Analyzed
5.3EPSS 0.003
CVE-2023-41295
Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim.
Published 2023-09-25 · Modified
5.3EPSS 0.003
CVE-2022-48296
The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.
Published 2023-02-09 · Modified
5.3EPSS 0.003
CVE-2023-34165
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.
Published 2023-06-16 · Modified
5.3EPSS 0.003
CVE-2023-41304
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.
Published 2023-10-11 · Modified
5.3EPSS 0.003
CVE-2023-52717
Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-04-07 · Analyzed
5.3EPSS 0.003
CVE-2023-52368
Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2024-02-18 · Analyzed
5.3EPSS 0.003
CVE-2025-53173
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
Published 2025-07-07 · Analyzed
5.3EPSS 0.002
CVE-2025-54650
Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.
Published 2025-08-06 · Analyzed
5.3EPSS 0.001
CVE-2023-52551
Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-04-08 · Analyzed
5.3EPSS 0.001
CVE-2025-54621
Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.
Published 2025-08-06 · Analyzed
5.3EPSS 0.001
CVE-2025-54619
Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.
Published 2025-08-06 · Analyzed
5.3EPSS 0.001
CVE-2026-34866
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
5.1EPSS 0.001
CVE-2025-54646
Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.
Published 2025-08-06 · Analyzed
5.1EPSS 0.001
CVE-2025-68961
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-01-14 · Analyzed
5.1EPSS 0.001
CVE-2025-68962
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-01-14 · Analyzed
5.1EPSS 0.001
← Prev25 / 27Next →