Junglewise Threat Intelligence

CVE-2026-34855: Huawei HarmonyOS and EMUI out-of-bounds write in kernel module

CVE-2026-34855 · Severity: medium · CVSS 5.7 · Published 2026-04-13

Technologies: Huawei Harmonyos, Huawei Emui. Vendors: Huawei.

Executive brief

A security vulnerability exists in the core software (kernel) of Huawei smartphones and tablets. If exploited, this could allow an attacker to crash the device or access sensitive information that should be protected. This issue affects various versions of HarmonyOS and EMUI software.

Technical details

An out-of-bounds write vulnerability exists in the kernel module of Huawei's HarmonyOS and EMUI operating systems due to improper input validation (CWE-20). The vulnerability is exploitable locally by an attacker with high privileges. Successful exploitation allows the attacker to write data outside the intended buffer boundaries in the kernel, which can lead to a system crash (denial of service) or unauthorized access to sensitive kernel memory (confidentiality impact). The issue is addressed in the April 2026 security update for affected Huawei flagship models.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1, 5.1.0, 6.0.0
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory: Huawei published the security bulletin.

References