Executive brief
The Honor E APP is affected by a security vulnerability that could allow unauthorized access to sensitive information. This application is used within the Honor device ecosystem, and a successful exploit could compromise the confidentiality of user data or service operations. This may lead to privacy concerns or the exposure of internal service details to unauthorized parties.
Technical details
Honor E APP contains an information leak vulnerability (CWE-200) that can be exploited over a network. The vulnerability root cause is an exposure of sensitive information to an unauthorized actor. According to the CVSS vector, the attack requires user interaction (UI:R) but no prior authentication (PR:N). Successful exploitation allows an attacker to read sensitive data, potentially affecting the confidentiality, integrity, and availability of the service. Honor has acknowledged the issue, though specific version fix details were not explicitly detailed in the initial advisory summary.
Affected products
- Honor E APP
Timeline
- 2026-04-21: disclosed: Initial disclosure by Honor Device Co., Ltd.
- 2026-04-21: advisory: NVD published the CVE record.