Junglewise Threat Intelligence

CVE-2026-34850: Huawei HarmonyOS race condition in notification service

CVE-2026-34850 · Severity: low · CVSS 1.9 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A race condition vulnerability exists in the notification service of Huawei HarmonyOS. This service is responsible for managing and displaying system and application alerts to the user. If exploited, the flaw could allow an attacker to disrupt the service, potentially leading to a partial loss of availability or system instability on affected smartphones, tablets, and PCs.

Technical details

A race condition vulnerability (CWE-362) exists in the notification service of Huawei HarmonyOS versions 5.1.0 and 6.0.0. The flaw stems from improper synchronization during concurrent execution using shared resources. An attacker with high privileges and local access could exploit this timing window to cause a denial-of-service condition. While the NVD lists a network-based vector with medium severity, the vendor (Huawei) specifies a local attack vector with high privileges required, resulting in a low CVSS score of 1.9. Security updates were released in April 2026 to address the issue.

Affected products

  • Huawei HarmonyOS 5.1.0, 6.0.0

Timeline

  • 2026-04-08: patched: Vendor update published for PCs.
  • 2026-04-13: disclosed: Initial CVE publication.
  • 2026-04-16: advisory: NIST NVD analysis completed.

References