Harmonyos
1,135 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Harmonyos, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Harmonyos CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 21 |
| 2024-12 | 26 |
| 2025-01 | 28 |
| 2025-02 | 10 |
| 2025-03 | 9 |
| 2025-04 | 20 |
| 2025-05 | 11 |
| 2025-06 | 11 |
| 2025-07 | 21 |
| 2025-08 | 49 |
| 2025-09 | 5 |
| 2025-10 | 21 |
| 2025-11 | 19 |
| 2025-12 | 17 |
| 2026-01 | 16 |
| 2026-02 | 18 |
| 2026-03 | 18 |
| 2026-04 | 20 |
| 2026-05 | 12 |
| 2026-06 | 15 |
| 2026-07 | 8 |
| 2026-08 | 10 |
| 2026-09 | 12 |
Severity
How the 1,135 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical131
- High507
- Medium454
- Low43
Latest CVEs
The 15 most recently published vulnerabilities affecting Harmonyos.
- CVE-2026-81645Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.5.9
- CVE-2026-49313Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.5.5
- CVE-2026-49309Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.4.8
- CVE-2026-41987Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.6.2
- CVE-2026-49315DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.7.1
- CVE-2026-81647Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.5.3
- CVE-2026-81646Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.5.9
- CVE-2026-81644DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.4.3
- CVE-2026-49312Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.4.0
- CVE-2026-49310Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.8.6
- CVE-2026-49314OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.7.3
- CVE-2026-49311Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.6.2
- CVE-2026-49303Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.5.1
- CVE-2026-49301Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.6.2
- CVE-2026-49305Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.6.2
Product grouping is registry-driven, with AI assist and human review. How it works