Junglewise Threat Intelligence

CVE-2026-41962: Huawei HarmonyOS permission control vulnerability in app management module

CVE-2026-41962 · Severity: low · CVSS 3.6 · Published 2026-05-15

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the application management component of Huawei HarmonyOS devices. If exploited, this flaw could allow unauthorized access to sensitive service information. This may lead to a breach of confidentiality for data managed by the affected system modules.

Technical details

A permission control vulnerability (CWE-264) exists in the app management and control module of Huawei HarmonyOS. The flaw is triggered locally and requires user interaction (UI:R), potentially involving a malicious application or file. Successful exploitation allows an attacker to bypass intended access restrictions to read sensitive service data, impacting confidentiality. The vulnerability affects HarmonyOS versions 6.0.0 and 6.1.0. Huawei has addressed this issue in the May 2026 security update.

Affected products

  • Huawei HarmonyOS 6.0.0, 6.1.0

Timeline

  • 2026-05-07: other: Bulletin updated by vendor
  • 2026-05-15: disclosed: NVD publication date

References

Related threats