Junglewise Threat Intelligence

CVE-2026-41969: Huawei HarmonyOS and EMUI permission control vulnerability in projection module

CVE-2026-41969 · Severity: medium · CVSS 6.2 · Published 2026-05-15

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the projection module of Huawei smartphones and tablets, which is used for sharing screens with external displays. If exploited, this flaw could allow unauthorized access to sensitive information on the device. This could lead to a breach of privacy or the exposure of confidential user data.

Technical details

A permission control vulnerability (CWE-275) exists in the projection module of Huawei HarmonyOS and EMUI. The flaw is rooted in improper enforcement of access rights within the component responsible for screen projection services. An attacker with physical access to the device and requiring user interaction could exploit this vulnerability to bypass intended restrictions. Successful exploitation allows the attacker to impact the confidentiality and integrity of the service. The vulnerability is addressed in the May 2026 security update for affected Huawei flagship models.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0

Timeline

  • 2026-05-15: disclosed
  • 2026-05-15: advisory

References

Related threats