CVE-2025-14817: Transsion Hios
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construct intents to directly open adb debugging functionality without user interaction.
Affected products
- Transsion Hios: version 14.0.0 only
Published 2025-12-17. Last modified 2026-09-28.