CVE-2025-27389 - CVE House
Back to Database
Status published Medium CVE-2025-27389

Application Installation Source Verification Flaw May Lead to Risk Detection Bypass

Vulnerability Description

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without proper warning.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27389

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ColorOS
Vulnerable Versions:
ColorOS 11–15

Timeline

Official Publish: December 5th, 2025
Last Modified: December 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)