📦 Harmonyos

by Huawei

🔍 What is Harmonyos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-28536

CRITICAL CVSS 9.6 Mar 5, 2026

This CVE describes an authentication bypass vulnerability in Huawei device authentication modules that allows attackers to bypass authentication mechanisms and gain unauthorized access. It affects mul...

CVE-2025-64314

CRITICAL CVSS 9.3 Nov 28, 2025

A permission control vulnerability in the memory management module allows unauthorized access to sensitive memory regions. This affects confidentiality by potentially exposing protected data. Huawei l...

CVE-2024-42037

CRITICAL CVSS 9.3 Aug 8, 2024

This vulnerability involves uncaught exceptions in the Graphics module that could allow attackers to access sensitive information. It affects systems running Huawei software with the vulnerable Graphi...

CVE-2024-39671

CRITICAL CVSS 9.3 Jul 25, 2024

This CVE describes an access control vulnerability in Huawei's security verification module that could allow unauthorized access to sensitive information. The vulnerability affects Huawei consumer dev...

CVE-2023-52538

CRITICAL CVSS 9.1 Apr 8, 2024

This vulnerability allows attackers to bypass package name verification in the HwIms module, potentially disrupting services. It affects Huawei devices running HarmonyOS with the vulnerable HwIms modu...

CVE-2024-30415

CRITICAL CVSS 9.1 Apr 7, 2024

This CVE describes an improper permission control vulnerability in the window management module of Huawei/HarmonyOS devices. Successful exploitation allows attackers to affect system availability, pot...

CVE-2023-52381

CRITICAL CVSS 9.8 Feb 18, 2024

This CVE describes a script injection vulnerability in Huawei's email module that allows attackers to execute arbitrary code. Successful exploitation could compromise confidentiality, integrity, and a...

CVE-2023-52378

CRITICAL CVSS 9.8 Feb 18, 2024

This vulnerability involves incorrect service logic in Huawei's WindowManagerServices module, allowing attackers to cause abnormal feature behavior. It affects Huawei devices running HarmonyOS. With a...

CVE-2023-52369

CRITICAL CVSS 9.1 Feb 18, 2024

A stack overflow vulnerability in the NFC module allows attackers to execute arbitrary code or cause denial of service. This affects Huawei devices running HarmonyOS with vulnerable NFC implementation...

CVE-2023-52101

CRITICAL CVSS 9.1 Jan 16, 2024

This CVE describes a component exposure vulnerability in Huawei Wi-Fi modules that could allow attackers to compromise service availability and integrity. The vulnerability affects Huawei devices runn...

CVE-2023-52103

CRITICAL CVSS 9.8 Jan 16, 2024

This CVE-2023-52103 is a critical buffer overflow vulnerability in Huawei's FLP module that allows out-of-bounds read attacks. Successful exploitation could lead to arbitrary code execution or system ...

CVE-2023-46773

CRITICAL CVSS 9.8 Dec 6, 2023

This CVE-2023-46773 is a permission management vulnerability in Huawei's PMS (Package Management Service) module that allows local attackers to escalate privileges on affected devices. The vulnerabili...

CVE-2023-5801

CRITICAL CVSS 9.1 Nov 8, 2023

This vulnerability allows attackers to bypass identity verification in the face unlock module on affected Huawei devices. Successful exploitation could compromise device integrity and confidentiality ...

CVE-2023-44116

CRITICAL CVSS 9.8 Oct 11, 2023

This vulnerability in Huawei's APPWidget module allows apps to run without proper authorization due to insufficient permission verification. It affects Huawei devices running HarmonyOS, potentially en...

CVE-2023-44105

CRITICAL CVSS 9.8 Oct 11, 2023

This CVE describes a critical privilege escalation vulnerability in Huawei/HarmonyOS window management modules where permissions are not strictly verified. Attackers can exploit this to gain elevated ...

CVE-2023-44106

CRITICAL CVSS 9.8 Oct 11, 2023

This CVE-2023-44106 is an API permission management vulnerability in Huawei's Fwk-Display module that allows unauthorized access to display framework functions. Successful exploitation could lead to a...

CVE-2023-41294

CRITICAL CVSS 9.8 Sep 25, 2023

The DP module in HarmonyOS has a service hijacking vulnerability that allows attackers to intercept or manipulate Super Device services. This affects HarmonyOS devices using the vulnerable DP module, ...

CVE-2023-41296

CRITICAL CVSS 9.1 Sep 25, 2023

This CVE-2023-41296 is a missing authorization vulnerability in a Huawei kernel module that allows unauthorized access to kernel functions. Successful exploitation could compromise system integrity an...

CVE-2023-39407

CRITICAL CVSS 9.1 Sep 25, 2023

CVE-2023-39407 is a path traversal vulnerability in Watchkit that allows unauthorized file access. Attackers can read or modify files outside intended directories, affecting confidentiality and integr...

CVE-2023-39402

CRITICAL CVSS 9.1 Aug 13, 2023

This CVE describes a parameter verification vulnerability in Huawei's installd module that allows unauthorized reading and writing of sandbox files. Attackers could potentially access or modify sensit...

CVE-2026-28542

HIGH CVSS 7.3 Mar 5, 2026

A permission bypass vulnerability in Huawei's system service framework allows attackers to circumvent intended access controls. This affects availability of Huawei consumer devices and wearables. User...

CVE-2026-28548

HIGH CVSS 7.1 Mar 5, 2026

This CVE describes an improper verification vulnerability in Huawei email applications that could allow attackers to access sensitive information. The vulnerability affects confidentiality by potentia...

CVE-2026-24930

HIGH CVSS 8.4 Feb 6, 2026

This CVE describes a use-after-free concurrency vulnerability in the graphics module that could allow an attacker to cause system instability or crashes. It primarily affects Huawei consumer devices w...

CVE-2025-68968

HIGH CVSS 7.8 Jan 14, 2026

A double free vulnerability in Huawei's multi-mode input module could allow attackers to execute arbitrary code or cause denial of service. This affects Huawei consumer devices with vulnerable input m...

CVE-2025-68958

HIGH CVSS 8.0 Jan 14, 2026

A race condition vulnerability in the card framework module allows attackers to disrupt system availability through multi-threaded exploitation. This affects Huawei consumer devices including laptops ...

CVE-2025-68960

HIGH CVSS 8.4 Jan 14, 2026

A race condition vulnerability in the video framework module allows attackers to cause denial of service by exploiting multi-threading timing issues. This affects Huawei devices with vulnerable video ...

CVE-2025-68957

HIGH CVSS 8.4 Jan 14, 2026

A race condition vulnerability in the card framework module allows attackers to disrupt system availability through multi-threaded exploitation. This affects Huawei consumer devices including laptops,...

CVE-2025-68955

HIGH CVSS 8.0 Jan 14, 2026

A race condition vulnerability in Huawei's card framework module allows attackers to disrupt system availability through multi-threaded exploitation. This affects Huawei consumer devices including lap...

CVE-2025-68956

HIGH CVSS 8.0 Jan 14, 2026

A race condition vulnerability in the card framework module allows attackers to cause denial of service by exploiting multi-threading issues. This affects Huawei consumer devices including laptops and...

CVE-2025-66327

HIGH CVSS 7.1 Dec 8, 2025

A race condition vulnerability in the network module could allow attackers to access sensitive information during concurrent operations. This affects Huawei products with the vulnerable network module...

CVE-2025-66328

HIGH CVSS 8.4 Dec 8, 2025

A race condition vulnerability in Huawei network management modules allows attackers to cause denial-of-service conditions by exploiting multi-threading timing issues. This affects Huawei network equi...

CVE-2025-66324

HIGH CVSS 8.4 Dec 8, 2025

This CVE describes an input verification vulnerability in Huawei's compression/decompression module that could allow attackers to manipulate or corrupt application data. The vulnerability affects Huaw...

CVE-2025-58302

HIGH CVSS 8.4 Nov 28, 2025

A permission control vulnerability in Huawei's Settings module allows unauthorized access to sensitive system settings. This affects Huawei devices running vulnerable firmware versions, potentially ex...

CVE-2025-58308

HIGH CVSS 7.3 Nov 28, 2025

This vulnerability involves improper security checks in a call module, allowing attackers to bypass intended restrictions. Successful exploitation could cause abnormal feature behavior, potentially le...

CVE-2025-58316

HIGH CVSS 7.3 Nov 28, 2025

This CVE describes a denial-of-service vulnerability in Huawei's video-related system service module. Attackers can exploit this vulnerability to crash or degrade the service, affecting availability. ...

CVE-2025-58303

HIGH CVSS 8.4 Nov 28, 2025

This CVE describes a use-after-free vulnerability in the screen recording framework module that could allow attackers to crash affected systems, potentially causing denial of service. The vulnerabilit...

CVE-2025-58310

HIGH CVSS 8.0 Nov 28, 2025

A permission control vulnerability in Huawei's distributed component allows unauthorized access to sensitive information. This affects Huawei products using the vulnerable distributed component, poten...

CVE-2025-58298

HIGH CVSS 7.3 Oct 11, 2025

A stack-based buffer overflow vulnerability (CWE-121) in Huawei's package management module allows attackers to cause denial of service by sending specially crafted data. This affects Huawei devices r...

CVE-2025-58287

HIGH CVSS 7.8 Oct 11, 2025

A Use After Free vulnerability in Huawei office service allows attackers to access sensitive information after memory has been freed. This affects Huawei devices running vulnerable versions of the off...

CVE-2025-54634

HIGH CVSS 8.0 Aug 6, 2025

This vulnerability involves improper handling of abnormal conditions during huge page separation in memory management. Successful exploitation could cause system crashes or denial of service, affectin...

CVE-2025-54627

HIGH CVSS 8.8 Aug 6, 2025

This CVE describes an out-of-bounds write vulnerability in the Skia graphics library. Successful exploitation could allow attackers to write beyond allocated memory boundaries, potentially leading to ...

CVE-2025-54622

HIGH CVSS 8.3 Aug 6, 2025

This CVE describes an authentication bypass vulnerability in Huawei's devicemanager module that allows attackers to access restricted functionality without proper credentials. It primarily affects Hua...

CVE-2025-54611

HIGH CVSS 7.3 Aug 6, 2025

The Gallery module in affected Huawei products contains an EXTRA_REFERRER resource read vulnerability that allows unauthorized access to sensitive information. This affects service confidentiality by ...

CVE-2025-54607

HIGH CVSS 7.7 Aug 6, 2025

This CVE describes an authentication management vulnerability in Huawei's ArkWeb module that could allow attackers to bypass authentication mechanisms. Successful exploitation may compromise service c...

CVE-2025-54655

HIGH CVSS 8.1 Aug 6, 2025

A race condition vulnerability in the virtualization base module could allow attackers to compromise the confidentiality and integrity of the virtualization graphics module. This affects systems using...

CVE-2025-54652

HIGH CVSS 8.4 Aug 6, 2025

A path traversal vulnerability (CWE-22) in Huawei's virtualization base module allows attackers to access files outside the intended directory. This affects systems running vulnerable Huawei virtualiz...

CVE-2025-53169

HIGH CVSS 7.6 Jul 7, 2025

This vulnerability allows unauthorized devices to bypass authentication and access distributed camera functions without user consent. It affects Huawei distributed camera systems where improper authen...

CVE-2025-48909

HIGH CVSS 7.1 Jun 6, 2025

This CVE describes an authentication bypass vulnerability in Huawei device management channels that could allow unauthorized access to management functions. Successful exploitation could compromise se...

CVE-2025-48911

HIGH CVSS 8.2 Jun 6, 2025

This vulnerability involves improper permission assignment in a note sharing module, allowing unauthorized access or manipulation of shared notes. Successful exploitation could disrupt availability of...

CVE-2025-48903

HIGH CVSS 7.8 Jun 6, 2025

A permission bypass vulnerability in the media library module allows unauthorized access to restricted media resources. This affects systems running the vulnerable software where the media library is ...

CVE-2025-48905

HIGH CVSS 8.1 Jun 6, 2025

This vulnerability in the arkweb v8 module allows WebAssembly (Wasm) exceptions to be improperly captured, potentially leading to application instability or crashes. It affects systems using Huawei's ...

CVE-2025-46584

HIGH CVSS 7.8 May 6, 2025

This CVE describes an improper authentication logic implementation in a file system module that could allow unauthorized access to sensitive data. Successful exploitation could compromise service conf...

CVE-2025-31175

HIGH CVSS 8.4 Apr 7, 2025

A deserialization mismatch vulnerability in the DSoftBus module allows attackers to manipulate serialized data to potentially execute arbitrary code or disrupt services. This affects systems running H...

CVE-2025-31170

HIGH CVSS 8.4 Apr 7, 2025

This CVE describes an access control vulnerability in Huawei's security verification module that allows attackers to bypass authentication mechanisms. Successful exploitation could compromise system i...

CVE-2025-31172

HIGH CVSS 7.8 Apr 7, 2025

This CVE describes a memory write permission bypass vulnerability in the Linux kernel's futex (fast userspace mutex) module. Attackers could potentially exploit this to write to kernel memory they sho...

CVE-2024-58124

HIGH CVSS 8.4 Apr 7, 2025

This CVE describes an access control vulnerability in Huawei's security verification module that allows attackers to bypass authentication mechanisms. Successful exploitation compromises system integr...

CVE-2024-58126

HIGH CVSS 8.4 Apr 7, 2025

This CVE describes an authentication bypass vulnerability in Huawei's security verification module that allows attackers to circumvent access controls. Successful exploitation could lead to unauthoriz...

CVE-2024-58111

HIGH CVSS 7.5 Apr 7, 2025

This vulnerability in the ArkUI framework's SVG parsing module allows attackers to cause denial of service by exploiting exception capture failures. It affects applications using ArkUI for SVG renderi...

CVE-2024-58107

HIGH CVSS 7.5 Apr 7, 2025

A buffer overflow vulnerability in the codec module could allow attackers to crash affected systems, potentially causing denial of service. This affects Huawei devices and software using the vulnerabl...

CVE-2024-58044

HIGH CVSS 8.4 Mar 4, 2025

This CVE describes a permission verification bypass vulnerability in Huawei's notification module that allows attackers to bypass intended access controls. Successful exploitation could disrupt system...

CVE-2026-28547

MEDIUM CVSS 6.8 Mar 5, 2026

This vulnerability involves uninitialized pointer access in a scanning module, which could cause crashes or denial of service. It affects Huawei consumer devices with vulnerable scanning software. The...

CVE-2026-28551

MEDIUM CVSS 4.7 Mar 5, 2026

A race condition vulnerability in Huawei device security management modules could allow attackers to disrupt system availability through timing-based attacks. This affects Huawei consumer devices incl...

CVE-2026-28544

MEDIUM CVSS 6.2 Mar 5, 2026

A race condition vulnerability in the printing module could allow attackers to disrupt printing services, potentially causing denial of service. This affects Huawei devices with vulnerable printing co...

CVE-2026-28550

MEDIUM CVSS 4.0 Mar 5, 2026

A race condition vulnerability in Huawei's security control module could allow attackers to disrupt system availability through timing-based attacks. This affects Huawei consumer devices running vulne...

CVE-2026-28537

MEDIUM CVSS 5.1 Mar 5, 2026

A double free vulnerability in the window module could allow attackers to crash affected systems, potentially causing denial of service. This affects Huawei consumer devices including laptops and othe...

CVE-2026-28539

MEDIUM CVSS 6.2 Mar 5, 2026

A data processing vulnerability in the certificate management module could allow attackers to access sensitive information. This affects Huawei consumer devices with vulnerable certificate management ...

CVE-2026-28541

MEDIUM CVSS 4.0 Mar 5, 2026

A permission control vulnerability in the cellular_data module could allow unauthorized access to cellular data functionality. This affects Huawei consumer devices including smartphones, laptops, wear...

CVE-2026-24920

MEDIUM CVSS 6.2 Feb 6, 2026

A permission control vulnerability in the AMS module could allow attackers to disrupt system availability. This affects Huawei devices running vulnerable versions of the AMS module. Users of affected ...

CVE-2026-24924

MEDIUM CVSS 6.1 Feb 6, 2026

This vulnerability involves improper permission control in the print module, allowing unauthorized access to sensitive information. It affects systems using the vulnerable print module and could compr...

CVE-2026-24927

MEDIUM CVSS 5.5 Feb 6, 2026

This CVE describes an out-of-bounds access vulnerability in a frequency modulation module that could allow attackers to cause denial of service conditions. The vulnerability affects availability of sy...

CVE-2026-24928

MEDIUM CVSS 5.8 Feb 6, 2026

This CVE describes an out-of-bounds write vulnerability in a file system module that could allow attackers to write data beyond allocated memory boundaries. Successful exploitation could affect servic...

CVE-2026-24929

MEDIUM CVSS 5.9 Feb 6, 2026

An out-of-bounds read vulnerability in the graphics module could allow attackers to read memory beyond allocated buffers, potentially causing application crashes or system instability. This affects Hu...

CVE-2026-24931

MEDIUM CVSS 5.9 Feb 6, 2026

This vulnerability involves an improper security check in the card module, potentially allowing unauthorized access to sensitive information. It affects Huawei devices with the vulnerable card module ...

CVE-2025-68970

MEDIUM CVSS 6.1 Jan 14, 2026

This CVE describes a permission verification bypass vulnerability in the media library module that allows unauthorized access to protected media content. It affects Huawei consumer devices with vulner...

CVE-2025-68964

MEDIUM CVSS 6.2 Jan 14, 2026

A data verification vulnerability in the HiView module could allow attackers to disrupt system availability by sending malformed data. This affects Huawei devices with the vulnerable HiView component....

CVE-2025-68965

MEDIUM CVSS 4.7 Jan 14, 2026

A permission control vulnerability in Huawei's Notepad module could allow unauthorized access to sensitive information. This affects users of Huawei consumer devices with the vulnerable Notepad softwa...

CVE-2025-68966

MEDIUM CVSS 5.1 Jan 14, 2026

A permission control vulnerability in Huawei's Notepad module could allow unauthorized access to sensitive information. This affects Huawei consumer devices with the vulnerable Notepad software instal...

CVE-2025-68967

MEDIUM CVSS 5.7 Jan 14, 2026

This vulnerability involves improper permission control in the print module, allowing unauthorized access to sensitive information. It affects Huawei devices with the vulnerable print module installed...

CVE-2025-68969

MEDIUM CVSS 6.8 Jan 14, 2026

A race condition vulnerability in the thermal management module allows concurrent threads to interfere with temperature control operations. This could lead to system instability or crashes, affecting ...

CVE-2025-68959

MEDIUM CVSS 6.2 Jan 14, 2026

This CVE describes a permission verification bypass vulnerability in the media library module that allows unauthorized access to protected media content. Attackers can exploit this flaw to view sensit...

CVE-2025-68961

MEDIUM CVSS 5.1 Jan 14, 2026

A race condition vulnerability in the camera framework module allows attackers to cause denial of service by exploiting multi-threading timing issues. This affects Huawei devices with vulnerable camer...

CVE-2025-68962

MEDIUM CVSS 5.1 Jan 14, 2026

A race condition vulnerability in the camera framework module allows attackers to cause denial of service by exploiting multi-threading timing issues. This affects Huawei devices with vulnerable camer...

CVE-2025-68963

MEDIUM CVSS 5.7 Jan 14, 2026

This CVE describes a man-in-the-middle (MITM) vulnerability in the Clone module that could allow attackers to intercept and potentially modify communications. The vulnerability affects service confide...

CVE-2025-66325

MEDIUM CVSS 6.2 Dec 8, 2025

A permission control vulnerability in Huawei's package management module could allow unauthorized access to sensitive information. This affects Huawei devices and systems using vulnerable package mana...

CVE-2025-66329

MEDIUM CVSS 4.0 Dec 8, 2025

A permission control vulnerability in Huawei's window management module could allow attackers to affect system availability. This vulnerability impacts Huawei consumer devices running affected softwar...

CVE-2025-66330

MEDIUM CVSS 4.9 Dec 8, 2025

This CVE describes an app lock verification bypass vulnerability in a file management application. Attackers could potentially access protected files without proper authentication, compromising data c...

CVE-2025-58279

MEDIUM CVSS 4.4 Dec 8, 2025

A permission control vulnerability in Huawei's media library module could allow unauthorized access to sensitive media files. This affects Huawei devices or systems using the vulnerable media library ...

CVE-2025-66326

MEDIUM CVSS 6.7 Dec 8, 2025

A race condition vulnerability in the audio module could allow attackers to cause denial of service by exploiting timing issues in audio processing. This affects Huawei devices with vulnerable audio c...

CVE-2025-66321

MEDIUM CVSS 5.1 Dec 8, 2025

A race condition vulnerability in Huawei's camera framework module allows attackers to disrupt camera functionality through multi-threaded timing attacks. This affects availability of camera services ...

CVE-2025-66322

MEDIUM CVSS 5.1 Dec 8, 2025

A race condition vulnerability in the camera framework module allows attackers to cause denial of service by exploiting multi-threading timing issues. This affects Huawei devices with vulnerable camer...

CVE-2025-66332

LOW CVSS 3.3 Dec 8, 2025

This CVE describes a denial of service vulnerability in Huawei office services where specially crafted requests could cause service disruption. The vulnerability affects Huawei products with office se...

CVE-2025-66333

LOW CVSS 3.3 Dec 8, 2025

This CVE describes a denial-of-service vulnerability in Huawei's office service. Successful exploitation could cause the service to become unresponsive or crash, affecting availability. Organizations ...

CVE-2025-66334

LOW CVSS 3.3 Dec 8, 2025

This CVE describes a denial of service vulnerability in Huawei office services where attackers can disrupt service availability. The vulnerability affects Huawei office products and services, potentia...

CVE-2025-66331

LOW CVSS 3.3 Dec 8, 2025

This CVE describes a denial-of-service vulnerability in Huawei office services where attackers can disrupt service availability. The vulnerability affects Huawei products running vulnerable versions o...