Executive brief
A permission control vulnerability exists in the manufacturability design module of Huawei HarmonyOS. This component is used in the design and manufacturing processes of mobile devices. If exploited, the flaw could allow an attacker to disrupt the availability of the device or its services, potentially leading to system instability or crashes.
Technical details
A permission control vulnerability (CWE-840: Business Logic Error) exists within the manufacturability design module of Huawei HarmonyOS. The vulnerability is characterized by improper enforcement of access controls, which can be exploited via a local attack vector without requiring special privileges or user interaction. Successful exploitation allows an attacker to impact the confidentiality, integrity, and availability of the affected system, though the primary reported impact is on service availability. The issue is addressed in the May 2026 security update for HarmonyOS versions 5.1.0, 6.0.0, and 6.1.0.
Affected products
- Huawei HarmonyOS 6.1.0, 6.0.0, 5.1.0
Timeline
- 2026-05-07: other: Advisory updated by vendor
- 2026-05-15: disclosed: NVD publication date