Impact
The vulnerability is a permission control flaw in the HarmonyOS app lock module. This flaw permits an attacker to bypass lock restrictions and access confidential service information that should be protected by the module.
Affected Systems
It affects Huawei HarmonyOS devices. Specific affected versions are not disclosed, but the problem exists in any build containing the vulnerable app lock module. Users should consult the Huawei support bulletin referenced for update details.
Risk and Exploitability
With a CVSS score of 5.5, the vulnerability represents moderate severity. The EPSS score is unavailable, so the exploitation probability is unknown. The issue is not listed in the CISA KEV catalog, suggesting no known public exploits. The attack vector is not specified; based on the nature of a permission control weakness, potential exploitation could be local or involve elevated privileges.
OpenCVE Enrichment