CVE-2025-58277
BaseFortify
Publication date: 2025-10-11
Last updated on: 2025-10-22
Assigner: Huawei Technologies
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| huawei | harmonyos | 5.0.1 |
| huawei | harmonyos | 5.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permission verification bypass in the Camera app, which means the app may fail to properly check if a user or process has the right permissions before allowing access. Exploiting this flaw could allow unauthorized access to camera services, potentially compromising service confidentiality.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing unauthorized entities to access camera services without proper permission, which may lead to exposure of confidential information captured or processed by the Camera app.