HarmonyOS vulnerabilities
CVEs whose affected-version data names the HarmonyOS package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-49313Medium· 5.5Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-81644Medium· 4.3DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49309Medium· 4.8Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-41987Medium· 6.2Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49314High· 7.3OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.
OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49312Medium· 4.0Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49311Medium· 6.2Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49310High· 8.6Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-81646Medium· 5.9Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-81647Medium· 5.3Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49315High· 7.1DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.