Junglewise Threat Intelligence

CVE-2026-34854: Huawei HarmonyOS and EMUI Use-After-Free in kernel module

CVE-2026-34854 · Severity: medium · CVSS 5.7 · Published 2026-04-13

Technologies: Huawei Harmonyos, Huawei Emui. Vendors: Huawei.

Executive brief

A security vulnerability exists in the core operating system software of Huawei smartphones and tablets. If exploited, this flaw could allow an attacker to crash the device or access sensitive information that should be protected. This could lead to service disruptions or the unauthorized viewing of private user data.

Technical details

A Use-After-Free (CWE-416) vulnerability exists within the kernel module of Huawei's HarmonyOS and EMUI operating systems. The flaw is triggered when the system attempts to use memory after it has been freed, which can be exploited by a local attacker with high privileges. Successful exploitation allows the attacker to compromise the confidentiality of system data or cause a denial-of-service (DoS) condition by affecting system availability. The vulnerability is addressed in the April 2026 security update for affected Huawei flagship models.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1, 5.1.0, 6.0.0
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory: Initial advisory published by Huawei
  • 2026-04-15: patched: NVD analysis and CPE information updated

References