Junglewise Threat Intelligence

CVE-2026-34849: Huawei HarmonyOS UAF in screen management module

CVE-2026-34849 · Severity: low · CVSS 2.5 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A vulnerability exists in the screen management module of Huawei HarmonyOS devices. This component is responsible for handling display and screen-related operations on smartphones and tablets. If exploited, the flaw could allow an attacker to cause system instability or a denial-of-service condition, potentially rendering the device unresponsive.

Technical details

A Use-After-Free (UAF) vulnerability exists in the screen management module of Huawei HarmonyOS. The vulnerability is rooted in a race condition (CWE-362) during concurrent execution using shared resources with improper synchronization. An attacker with local access and low privileges could exploit this flaw, though it requires a high degree of complexity or specific timing to trigger. Successful exploitation leads to a denial-of-service (DoS) condition affecting the availability of the system. The issue is addressed in the April 2026 security update for HarmonyOS versions 5.1.0 and 6.0.0.

Affected products

  • Huawei HarmonyOS 5.1.0, 6.0.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory: Huawei published security bulletin
  • 2026-04-14: other: NVD initial analysis completed

References