CVE Tools

Harmonyos

1,135 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Harmonyos, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Harmonyos CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Harmonyos CVEs per month
MonthCVEs
2024-100
2024-1121
2024-1226
2025-0128
2025-0210
2025-039
2025-0420
2025-0511
2025-0611
2025-0721
2025-0849
2025-095
2025-1021
2025-1119
2025-1217
2026-0116
2026-0218
2026-0318
2026-0420
2026-0512
2026-0615
2026-078
2026-0810
2026-0912

Severity

How the 1,135 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical13112%
  • High50745%
  • Medium45440%
  • Low434%

Latest CVEs

The 15 most recently published vulnerabilities affecting Harmonyos.

  1. CVE-2026-81645Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.5.9
  2. CVE-2026-49313Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.5.5
  3. CVE-2026-49309Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.4.8
  4. CVE-2026-41987Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.6.2
  5. CVE-2026-49315DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.7.1
  6. CVE-2026-81647Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.5.3
  7. CVE-2026-81646Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.5.9
  8. CVE-2026-81644DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.4.3
  9. CVE-2026-49312Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.4.0
  10. CVE-2026-49310Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.8.6
  11. CVE-2026-49314OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.7.3
  12. CVE-2026-49311Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability may affect availability.6.2
  13. CVE-2026-49303Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.5.1
  14. CVE-2026-49301Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.6.2
  15. CVE-2026-49305Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.6.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store