Junglewise Threat Intelligence

CVE-2026-34857: Huawei HarmonyOS use-after-free in communication module

CVE-2026-34857 · Severity: medium · CVSS 4.7 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the communication module of Huawei HarmonyOS, which is used in smartphones, tablets, smartwatches, and Vision devices. A successful exploit could allow an attacker to cause system instability or a service outage, potentially disrupting the normal operation of the device. This issue primarily impacts the availability of the device's communication features.

Technical details

A Use-After-Free (UAF) vulnerability exists in the communication module of Huawei HarmonyOS. The flaw is rooted in a race condition (CWE-362) during concurrent execution using shared resources with improper synchronization. An attacker with high privileges can exploit this locally to trigger the UAF condition. Successful exploitation can lead to a partial impact on confidentiality and a high impact on system availability (denial of service). The vulnerability affects HarmonyOS versions 5.1.0, 5.1.1, and 6.0.0, and has been addressed in the April 2026 security updates.

Affected products

  • Huawei HarmonyOS 5.1.0, 5.1.1, 6.0.0

Timeline

  • 2026-04-08: patched: Huawei released security bulletins addressing the issue.
  • 2026-04-13: disclosed: Initial publication of the CVE.
  • 2026-04-15: advisory: NVD published initial analysis.

References