Executive brief
A security vulnerability has been identified in the web component of Huawei HarmonyOS, which is used across various smartphones, tablets, and PCs. If exploited, this flaw could allow an attacker to disrupt the normal operation of the device, potentially leading to service outages or system instability. This issue primarily impacts the availability of the device's web-based services and features.
Technical details
A permission control vulnerability exists in the web component of Huawei HarmonyOS versions 6.0.0 and 6.1.0. The vulnerability is classified as a race condition (CWE-362), where concurrent execution using shared resources is improperly synchronized. An attacker with local access can exploit this flaw to bypass intended permission restrictions. Successful exploitation can result in high impacts to confidentiality, integrity, and availability, though the primary impact highlighted by the vendor is the disruption of service availability. Patches have been released as part of the May 2026 security update cycle.
Affected products
- Huawei HarmonyOS 6.0.0, 6.1.0
Timeline
- 2026-05-07: patched: Security bulletin updated with fix information
- 2026-05-15: disclosed: CVE published to NVD dataset