CVE-2021-22420

HIGH

HarmonyOS - Privilege Escalation

Title source: llm

Description

A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-668
Status published

Affected Products (1)

huawei/harmonyos

Timeline

Published Aug 03, 2021
Tracked Since Feb 18, 2026