Junglewise Threat Intelligence

CVE-2026-34866: Huawei HarmonyOS out-of-bounds write in WEB module

CVE-2026-34866 · Severity: medium · CVSS 5.1 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the web browsing component of Huawei HarmonyOS, primarily affecting smartwatches. If exploited, this flaw could allow an attacker to disrupt the device's normal operation or potentially access restricted information. This could lead to device instability or unauthorized data access on the affected wearable.

Technical details

An out-of-bounds write vulnerability (CWE-120) exists in the WEB module of Huawei HarmonyOS 6.0.0. The flaw is caused by a buffer copy operation that does not properly check the size of the input. An attacker with local access can exploit this to write data beyond the intended buffer limits. This can lead to memory corruption, potentially resulting in a denial-of-service (affecting availability) or unauthorized access to sensitive data (affecting confidentiality). The vulnerability was addressed in the April 2026 security update for Huawei smartwatches.

Affected products

  • Huawei HarmonyOS 6.0.0

Timeline

  • 2026-04-08: advisory: Huawei published the security bulletin for smartwatches.
  • 2026-04-13: disclosed: CVE published to NVD.

References

Related threats