Impact
The vulnerability is a permission control flaw in Huawei HarmonyOS’s clipboard module that permits unauthorized applications to read clipboard contents, exposing sensitive data such as passwords, credit card numbers, or personal messages. This weakness, identified as CWE‑264, enables a confidentiality breach when an attacker can run code or manipulate an application that accesses the clipboard.
Affected Systems
Huawei HarmonyOS devices are impacted. No specific version information is provided, so any installation that includes the vulnerable clipboard component is at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. The likely attack vector is local: an attacker must be able to run code or trick an application into accessing the clipboard. Remote exploitation is unlikely without additional conditions. The impact is limited to confidentiality, as the flaw does not affect integrity or availability.
OpenCVE Enrichment