Junglewise Threat Intelligence

CVE-2026-34867: Huawei HarmonyOS double free in multi-mode input system

CVE-2026-34867 · Severity: medium · CVSS 5.6 · Published 2026-04-13

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A vulnerability exists in the multi-mode input system of Huawei HarmonyOS, which manages how the device processes various user inputs. If exploited, this flaw could allow an attacker to cause the system to crash or become unresponsive, impacting the device's availability. This affects Huawei smartphones, tablets, and PCs running specific versions of HarmonyOS.

Technical details

A double free vulnerability (CWE-415) exists within the multi-mode input system of Huawei HarmonyOS. The flaw is triggered when the system attempts to free the same memory location twice, leading to potential memory corruption. An attacker with local access and low privileges can exploit this by inducing a specific user interaction, resulting in a system crash or denial of service (DoS). The vulnerability is tracked as CVE-2026-34867 and has been addressed in the April 2026 security updates for affected Huawei devices.

Affected products

  • Huawei HarmonyOS 5.1.0, 6.0.0

Timeline

  • 2026-04-08: patched: Huawei released security bulletin updates.
  • 2026-04-13: disclosed: CVE published to NVD.

References