Junglewise Threat Intelligence

CVE-2026-34859: Huawei HarmonyOS and EMUI Use-After-Free in kernel module

CVE-2026-34859 · Severity: medium · CVSS 5.9 · Published 2026-04-13

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the core software (kernel) of Huawei smartphones, tablets, and smart screens. If exploited, this could allow an attacker to crash the device or gain unauthorized access to sensitive information. Users should apply the April 2026 security updates to protect their devices.

Technical details

A Use-After-Free (UAF) vulnerability (CWE-416) exists within the kernel module of Huawei's HarmonyOS and EMUI operating systems. The flaw is triggered when the system continues to use a memory pointer after it has been freed, which can be exploited by a local attacker with low privileges. Successful exploitation allows the attacker to compromise system confidentiality and availability, potentially leading to arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability was addressed in the April 2026 security bulletin.

Affected products

  • Huawei HarmonyOS 4.2.0, 4.3.0
  • Huawei EMUI 14.2.0, 15.0.0

Timeline

  • 2026-04-08: patched: Huawei released security bulletin updates.
  • 2026-04-13: disclosed: Initial CVE publication.
  • 2026-04-15: advisory: NVD updated with NIST analysis and CVSS scoring.

References