Junglewise Threat Intelligence

CVE-2026-31368: Honor AiAssistant privilege bypass

CVE-2026-31368 · Severity: high · CVSS 7.8 · Published 2026-04-21

Executive brief

Honor's AiAssistant is affected by a security flaw that allows an attacker to bypass intended permission levels. This could allow a malicious actor already on the device to gain unauthorized access to sensitive data or disrupt the availability of the assistant's services. Such an exploit could compromise user privacy and the reliability of the device's AI features.

Technical details

A privilege management vulnerability (CWE-269) exists in the Honor AiAssistant component. The flaw allows a local attacker with low-level privileges to bypass type-based access controls. Successful exploitation can lead to a complete compromise of confidentiality, integrity, and availability (CVSS 7.8). The vulnerability is triggered locally without requiring user interaction. Honor has acknowledged the issue, though specific patched version numbers were not detailed in the initial advisory.

Affected products

  • Honor AiAssistant

Timeline

  • 2026-04-21: disclosed: Initial disclosure by Honor Device Co., Ltd.
  • 2026-04-21: advisory
  • 2026-05-10: other: NVD record updated by CISA-ADP with CWE-269 classification.

References