Junglewise Threat Intelligence

CVE-2026-41960: Huawei HarmonyOS and EMUI permission control vulnerability in calls

CVE-2026-41960 · Severity: medium · CVSS 5.8 · Published 2026-05-15

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security flaw has been identified in the calling functionality of Huawei smartphones and tablets. This vulnerability could allow an attacker to disrupt the availability of phone services or potentially access limited information. Successful exploitation requires a user to perform a specific action, such as clicking a malicious link, while the attacker operates under specific network conditions.

Technical details

A permission control vulnerability exists in the 'calls' component of Huawei's HarmonyOS and EMUI operating systems. Classified under CWE-200 (Exposure of Sensitive Information), the flaw is triggered via a network attack vector with high complexity, requiring user interaction. An attacker successfully exploiting this vulnerability can impact the availability of the calling service and achieve limited confidentiality and integrity impacts. The vulnerability affects HarmonyOS versions 4.0.0 through 4.3.1 and EMUI versions 14.0.0 through 15.0.0. Patches were released in the May 2026 security update.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0

Timeline

  • 2026-05-07: patched: Huawei released security bulletin update.
  • 2026-05-15: disclosed: CVE published to NVD.

References

Related threats