Description
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-08-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permission control flaw in Huawei HarmonyOS’s clipboard module that permits unauthorized applications to read clipboard contents, exposing sensitive data such as passwords, credit card numbers, or personal messages. This weakness, identified as CWE‑264, enables a confidentiality breach when an attacker can run code or manipulate an application that accesses the clipboard.

Affected Systems

Huawei HarmonyOS devices are impacted. No specific version information is provided, so any installation that includes the vulnerable clipboard component is at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. The likely attack vector is local: an attacker must be able to run code or trick an application into accessing the clipboard. Remote exploitation is unlikely without additional conditions. The impact is limited to confidentiality, as the flaw does not affect integrity or availability.

Generated by OpenCVE AI on August 17, 2026 at 11:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HarmonyOS firmware update that includes the clipboard module fix
  • Disable or limit clipboard sharing between applications through device settings
  • Restrict applications’ access to the clipboard by reviewing and editing permission settings in the app manager
  • Monitor system logs for anomalous clipboard activity indicating potential exploitation

Generated by OpenCVE AI on August 17, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Clipboard Permission Control Weakness in Huawei HarmonyOS

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-17T10:56:46.473Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49308

cve-icon Vulnrichment

Updated: 2026-08-17T10:56:40.962Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:31.010

Modified: 2026-08-26T16:33:17.117

Link: CVE-2026-49308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:30:05Z

Weaknesses