← back
CVE-2025-27389

Application Installation Source Verification Flaw May Lead to Risk Detection Bypass

CVSS 5.1 MEDIUMEPSS 0.1%CWE-290
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without proper warning.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
ColorOS · ColorOS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →