Hihonor's vulnerability profile centers on a focused portfolio of mobile operating systems and device firmware, including Magic UI, Magic OS, and associated device firmware for products such as the Nth-AN00, representing a moderately prominent but constrained attack surface. The recurring weakness classes span privilege management, type confusion, cryptographic signature verification, and out-of-bounds read conditions, reflecting the memory-safety and access-control complexity inherent to mobile operating system kernels and firmware subsystems. The vendor's disclosures demonstrate a meaningful share reaching serious severity, warranting attention from defenders managing affected devices. Vulnerabilities in mobile platform firmware tend to persist across device generations where firmware updates lag behind OS releases, making inventory and patch coordination particularly challenging. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hihonor over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2188CRITICAL There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity. | Apr 17, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-1532CRITICAL Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity. | Apr 17, 2025 | 9.1 | 26 | NO | NO |
CVE-2026-22419HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Honor honor allows PHP Local File Inclusion.Th | Mar 5, 2026 | 8.1 | 25 | NO | NO |
CVE-2023-23424CRITICAL
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
| Dec 29, 2023 | 9.8 | 25 | NO | NO |
CVE-2025-46014HIGH Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive sec | Jun 30, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-47151HIGH Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | Dec 26, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-51434HIGH
Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution.
| Dec 29, 2023 | 7.8 | 21 | NO | NO |
CVE-2023-23431HIGH
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
| Dec 29, 2023 | 7.1 | 21 | NO | NO |
CVE-2023-51435HIGH
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
| Dec 29, 2023 | 7.1 | 20 | NO | NO |
CVE-2023-51428HIGH
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
| Dec 29, 2023 | 7.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hihonor.
Media articles that mention a CVE ID that affects a product developed by Hihonor — matched by CVE ID, not by vendor name.