Junglewise Threat Intelligence

CVE-2026-34865: Huawei HarmonyOS out-of-bounds write in WEB module

CVE-2026-34865 · Severity: critical · CVSS 9.1 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability has been identified in the web browsing component of Huawei smartwatches running HarmonyOS. This flaw could allow an attacker to disrupt the device's operation or potentially access private information. Successful exploitation could lead to device instability or unauthorized data exposure, impacting the privacy and reliability of the wearable device.

Technical details

An out-of-bounds write vulnerability (specifically a heap-based buffer overflow, CWE-122) exists in the WEB module of Huawei HarmonyOS 6.0.0. The flaw allows an attacker to write data past the end of an intended buffer, which can lead to memory corruption. According to the CVSS metrics, this is a network-reachable vulnerability that requires no prior authentication or user interaction. Exploitation can result in a denial-of-service condition or unauthorized access to sensitive information. Huawei has addressed this issue in the April 2026 security update for smartwatches.

Affected products

  • Huawei HarmonyOS 6.0.0

Timeline

  • 2026-04-08: patched: Huawei released the security bulletin for smartwatches.
  • 2026-04-13: disclosed: Initial publication of the CVE.

References

Related threats