Executive brief
A security vulnerability exists in the manufacturability design module of Huawei HarmonyOS. This module is part of the system's design and production framework. If exploited, an attacker could disrupt the availability of the device or its services, potentially leading to system instability or crashes.
Technical details
A permission control vulnerability (CWE-840: Business Logic Error) exists in the manufacturability design module of Huawei HarmonyOS versions 5.1.0 and 6.0.0. The flaw allows for improper enforcement of access controls, which can be exploited via a local attack vector without requiring special privileges or user interaction. Successful exploitation allows an attacker to impact the availability, confidentiality, and integrity of the affected component, though the primary reported impact is on system availability. The vulnerability was addressed in the Huawei May 2026 security update.
Affected products
- Huawei HarmonyOS 5.1.0, 6.0.0
Timeline
- 2026-05-15: disclosed: Initial publication of the CVE record and Huawei security bulletin.