Impact
The vulnerability is a permission control weakness in the window module of Huawei HarmonyOS. It allows an attacker who can exploit the flaw to gain unauthorized access to confidential service data. The flaw is an authorization bypass, denoted by CWE-264, which can compromise confidentiality but does not elevate privileges system‑wide or cause denial of service.
Affected Systems
All Huawei HarmonyOS devices that include the affected window module are at risk. No specific firmware or OS version numbers are provided, so any device running the window module with the bug is considered vulnerable unless a later update removes the flaw.
Risk and Exploitability
The CVSS score for this vulnerability is 4, indicating a moderate risk level. EPSS data is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited in the wild yet. As the weakness involves permission control, an attacker would likely need local or remote access with sufficient rights to interact with the window module, and the exploit would successfully allow them to read protected service information.
OpenCVE Enrichment