CVE-2025-27389EPSS p2.3%

CVE-2025-27389CVE-2025-27389

Description

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without proper warning.

Scoring

EPSS0.13% probability of exploitation · percentile 2.3% · 2026-10-05T12:00:23Z
Last modified2026-09-25
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.