Executive brief
A security vulnerability exists in the communication module of Huawei HarmonyOS, which is used in smartphones, tablets, smartwatches, and Vision devices. A successful exploit could allow an attacker to cause system instability or a service outage, potentially disrupting the normal operation of the device. This issue primarily impacts the availability of the device's communication features.
Technical details
A Use-After-Free (UAF) vulnerability exists in the communication module of Huawei HarmonyOS. The flaw is rooted in a race condition (CWE-362) during concurrent execution using shared resources with improper synchronization. An attacker with high privileges can exploit this locally to trigger the UAF condition. Successful exploitation can lead to a partial impact on confidentiality and a high impact on system availability (denial of service). The vulnerability affects HarmonyOS versions 5.1.0, 5.1.1, and 6.0.0, and has been addressed in the April 2026 security updates.
Affected products
- Huawei HarmonyOS 5.1.0, 5.1.1, 6.0.0
Timeline
- 2026-04-08: patched: Huawei released security bulletins addressing the issue.
- 2026-04-13: disclosed: Initial publication of the CVE.
- 2026-04-15: advisory: NVD published initial analysis.