A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without proper warning.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oppo
Oppo coloros |
|
| Vendors & Products |
Oppo
Oppo coloros |
Fri, 05 Dec 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without proper warning. | |
| Title | Application Installation Source Verification Flaw May Lead to Risk Detection Bypass | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: OPPO
Published: 2025-12-05T03:19:49.490Z
Updated: 2025-12-05T16:20:31.736Z
Reserved: 2025-02-24T03:04:32.845Z
Link: CVE-2025-27389
Updated: 2025-12-05T16:20:27.840Z
Status : Received
Published: 2025-12-05T04:16:00.333
Modified: 2025-12-05T04:16:00.333
Link: CVE-2025-27389
No data.