harmonyos-iap-integration
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalyreferences/client-arkts.md
LOWAnomalyLOW
references/client-arkts.md
No direct supply-chain malware indicators are evident in the provided fragment (no obfuscation/payload execution, no exfiltration, no backdoor behavior). The dominant security concern is an integrity gap: JWSUtil only decodes the JWS payload and does not verify signatures/authenticity, yet decoded fields are used to make entitlement decisions and to call finishPurchase. Treat this as a trust-boundary weakness requiring proper JWS verification (and/or backend verification) before production use.
Confidence: 62%Severity: 56%
Audit Metadata