CVE-2026-22070
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@oppo.com — https://security.oppo.com/en/noticeDetail?notice_only_key=NOTICE-2049764240746881024
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| oppo | coloros_assistant | 1.4.26 | |
References
CWEs
CWE-23 CWE-22
Verify integrity in audit chain (admin only). AS-IS.