Junglewise Threat Intelligence

CVE-2026-34863: Huawei HarmonyOS out-of-bounds write in file system

CVE-2026-34863 · Severity: medium · CVSS 6.7 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability has been identified in the file system of Huawei HarmonyOS, the operating system used in many Huawei smartphones and tablets. An attacker with high-level privileges could exploit this flaw to cause system instability or a complete service outage. This could disrupt business operations and prevent users from accessing their devices or data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the file system component of Huawei HarmonyOS versions 5.1.0 and 6.0.0. The flaw is triggered when the system fails to properly validate the boundaries of a buffer during file system operations. An attacker with high privileges (PR:H) can exploit this locally to write data beyond the intended buffer, potentially leading to memory corruption. While the primary impact reported is on system availability, the vendor's CVSS vector also suggests potential impacts on confidentiality and integrity. A patch was released as part of the April 2026 security bulletin.

Affected products

  • Huawei HarmonyOS 5.1.0, 6.0.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory: Huawei published the April 2026 security bulletin.

References