Impact
A permission control flaw exists in HarmonyOS’s notification service module. The vulnerability allows an attacker to read data from the notification service that should be confidential, potentially exposing sensitive information related to the service’s operation. This weakness is classified as CWE‑200 and can lead to a compromise of service confidentiality.
Affected Systems
Huawei HarmonyOS devices are affected. No specific version numbers are provided, so all current releases should be considered at risk until a public patch is issued.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be local or through the delivery of crafted notifications, requiring interaction with the notification service. No information is available on remote exploitability or prerequisites beyond the presence of the vulnerable service.
OpenCVE Enrichment