Junglewise Threat Intelligence

CVE-2026-34862: Huawei HarmonyOS race condition in power consumption statistics module

CVE-2026-34862 · Severity: medium · CVSS 6.3 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A race condition vulnerability exists in the power consumption statistics module of Huawei HarmonyOS. This module is responsible for tracking and reporting battery usage across the device. If exploited, an attacker could cause the system to become unstable or unavailable, potentially disrupting normal device operations.

Technical details

A race condition vulnerability (CWE-362) exists within the power consumption statistics module of Huawei HarmonyOS 6.0.0. The flaw occurs due to improper synchronization when multiple processes or threads access shared resources within the module. An attacker with high privileges can exploit this locally to trigger the race condition. Successful exploitation primarily impacts system availability, though vendor metrics also suggest potential minor impacts on confidentiality and integrity. Patches were released as part of the April 2026 security update for Huawei phones, tablets, and smartwatches.

Affected products

  • Huawei HarmonyOS 6.0.0

Timeline

  • 2026-04-08: other: Vendor advisory updated
  • 2026-04-13: disclosed: NVD publication date

References

Related threats