Impact
Huawei HarmonyOS contains a permission control flaw within its multi‑mode input module. An attacker who can circumvent the intended permission checks could read or capture sensitive service data. This vulnerability is tied to CWE‑200 and results in the loss of confidentiality for the affected services.
Affected Systems
The flaw is present in Huawei HarmonyOS. No specific version information is given in the advisory, so all released HarmonyOS builds remain at risk until a patch is deployed.
Risk and Exploitability
The CVSS score is 6.2, indicating a moderate severity level. EPSS information is not available and the issue is not listed in the CISA KEV catalog, so there is no current evidence of exploitation in the wild. The attack vector is not explicitly stated, but the multi‑mode input module suggests that local or semi‑local interaction may suffice to abuse the permission controls. Overall risk to confidentiality is moderate, requiring timely remediation.
OpenCVE Enrichment