harmonyos vulnerabilities
CVEs whose affected-version data names the harmonyos package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
16 CVEsRSS
CVE-2026-81645Medium· 5.9Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.
Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.
CVE-2026-49313Medium· 5.5Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-81644Medium· 4.3DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49309Medium· 4.8Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-41987Medium· 6.2Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49314High· 7.3OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.
OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49312Medium· 4.0Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49311Medium· 6.2Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49310High· 8.6Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-81646Medium· 5.9Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-81647Medium· 5.3Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49315High· 7.1DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-64313Medium· 5.3Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-58316High· 7.3DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-58312Medium· 5.1Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-58298High· 7.3Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.
Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.