Executive brief
A race condition vulnerability exists in the event notification module of Huawei HarmonyOS, which is used in smartphones, tablets, and PCs. If exploited, this flaw could allow an attacker to disrupt the normal operation of the device's notification system, potentially leading to service instability or a temporary loss of availability for certain features. This issue was addressed in the April 2026 security update.
Technical details
A race condition vulnerability (CWE-362) exists in the event notification module of Huawei HarmonyOS versions 5.1.0 and 6.0.0. The flaw stems from improper synchronization when multiple processes or threads access shared resources within the notification service. An attacker with local access and low privileges could exploit this by timing specific inputs or actions, requiring user interaction and high attack complexity. Successful exploitation results in a denial-of-service condition affecting the availability of the notification module. Huawei has released patches for this vulnerability in its April 2026 security bulletin.
Affected products
- Huawei HarmonyOS 5.1.0, 6.0.0
Timeline
- 2026-04-08: patched: Huawei released security bulletin for PCs.
- 2026-04-13: disclosed: CVE published by Huawei.
- 2026-04-16: advisory: NVD initial analysis completed.