Huawei HarmonyOS and EMUI Input Verification Vulnerability in External Storage Provider Module

Vulnerability

A vulnerability has been identified in the ExternalStorageProvider module of Huawei's HarmonyOS and EMUI versions. This vulnerability arises from inadequate input verification, which could be exploited to affect the confidentiality of services.

Impact

Exploitation of this vulnerability may lead to unauthorized access to sensitive information, compromising service confidentiality.

Remediation

Users can apply the February 2025 security update to address this vulnerability. Instructions for downloading this update are available on the Huawei Support website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.