Executive brief
A security flaw has been identified in the window management module of Huawei's HarmonyOS and EMUI operating systems, which are used on smartphones, tablets, and smart displays. This vulnerability involves improper permission controls that could allow an attacker to disrupt the device's normal operation. Successful exploitation could lead to service instability or a denial-of-service condition, impacting the availability of the device for the user.
Technical details
A permission control vulnerability exists within the window management module of Huawei HarmonyOS and EMUI. The flaw is categorized under CWE-264 (Permissions, Privileges, and Access Controls) and stems from insufficient validation of access rights within the windowing subsystem. An attacker with local access to the device could exploit this vulnerability to trigger a denial-of-service (DoS) state, affecting the availability of the system's graphical interface or general services. The vulnerability affects a wide range of versions including HarmonyOS 2.0.0 through 4.3.1 and EMUI 12.0.0 through 15.0.0. Patches have been released as part of the December 2025 and June 2026 security bulletins.
Affected products
- Huawei HarmonyOS 2.0.0, 3.0.0, 3.1.0, 4.0.0, 4.2.0, 4.3.0, 4.3.1
- Huawei EMUI 12.0.0, 13.0.0, 14.0.0, 14.2.0, 15.0.0
Timeline
- 2025-12-05: advisory: Initial Huawei security bulletin published
- 2025-12-08: disclosed: NVD publication date
- 2026-06-05: advisory: Updated Huawei Vision security bulletin published