Executive brief
A race condition vulnerability exists in the thermal management module of Huawei HarmonyOS devices, including smartphones, tablets, and smartwatches. This module is responsible for monitoring and regulating device temperature to prevent overheating. If exploited, this flaw could allow an attacker to disrupt the device's normal operations, potentially leading to system instability or a complete loss of availability.
Technical details
A race condition vulnerability (CWE-362) exists within the thermal management module of Huawei HarmonyOS 6.0.0. The flaw stems from improper synchronization when multiple processes or threads access shared resources related to temperature regulation. An attacker with high privileges can exploit this local vulnerability to cause a denial-of-service condition or otherwise impact the availability of the system. While the NVD and Huawei provide slightly different CVSS vectors, the vendor-supplied vector (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H) indicates that while the attack is local and requires high privileges, it has a significant impact on integrity and availability. Patches were released as part of the April 2026 security update.
Affected products
- Huawei HarmonyOS 6.0.0
Timeline
- 2026-04-08: patched: Huawei released security bulletins for phones, tablets, and wearables.
- 2026-04-13: disclosed: CVE published to NVD.