Executive brief
A memory management vulnerability exists in the web component of Huawei HarmonyOS, which is used in smartphones, tablets, and PCs. If exploited, this flaw could allow an attacker to disrupt the device's stability or cause service outages, potentially impacting business operations and user productivity. The issue is addressed in the May 2026 security updates for affected flagship models.
Technical details
A Use-After-Free (UAF) vulnerability exists within the 'web' component of Huawei HarmonyOS versions 6.0.0 and 6.1.0. The flaw is categorized under CWE-840 (Business Logic Errors) by the vendor, though the primary mechanism is a memory corruption issue where the system continues to use a pointer after it has been freed. According to the CVSS:3.1 vector, the attack vector is network-based with high complexity and requires no privileges or user interaction. Successful exploitation can lead to a loss of availability (DoS) and limited impact on confidentiality and integrity. Patches were released as part of the Huawei May 2026 security bulletin.
Affected products
- Huawei HarmonyOS 6.0.0, 6.1.0
Timeline
- 2026-05-07: patched: Huawei released security bulletin updates.
- 2026-05-15: disclosed: CVE published to NVD.