CVE-2025-54611

7.3

Huawei · HarmonyOS, EMUI

A business logic error in the Gallery module of Huawei HarmonyOS and EMUI allows for unauthorized resource reading, potentially impacting the confidentiality of user data.

Executive summary

A business logic vulnerability in the Huawei Gallery module affects multiple versions of HarmonyOS and EMUI, posing a risk to data confidentiality.

Vulnerability

The vulnerability is a business logic error (CWE-840) within the Gallery module that permits unauthorized resource reading. Based on the CVSS vector (AV:L/PR:N/UI:N), the exploit requires local access to the device but does not require user interaction or elevated privileges to trigger.

Business impact

The exploitation of this flaw may lead to the unauthorized disclosure of sensitive information stored within the Gallery application. With a CVSS score of 7.3, this is considered a High severity issue, as it compromises the fundamental confidentiality of user assets, potentially leading to privacy violations or exposure of personal media.

Remediation

Immediate Action: Users should check for and apply the latest security updates provided by Huawei through the official system update interface as detailed in the August 2025 security bulletin.

Proactive Monitoring: Security teams or users should monitor for unusual application behavior or unexpected permission requests associated with the Gallery module.

Compensating Controls: Ensure that device-level security features, such as screen locks and file-based encryption, are strictly enforced to limit the potential for unauthorized local access to the device.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the High severity rating, administrators and users must prioritize the deployment of vendor-supplied patches as soon as they become available. Failure to update the affected Huawei devices leaves the Gallery module susceptible to unauthorized data access, and immediate patching is the only effective way to remediate this logic-based exposure.

Sources