Executive brief
A security vulnerability has been identified in the distributed file system module of Huawei mobile devices and smartwatches. This component is responsible for managing files across different connected devices. If exploited, this flaw could allow an attacker to disrupt the device's stability or cause it to crash, potentially impacting the availability of the device and its services.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the distributed file system module of Huawei's HarmonyOS and EMUI operating systems. The vulnerability is triggered when the system writes data outside the boundaries of the intended memory buffer. An attacker with adjacent network access and low-level privileges can exploit this to cause memory corruption. The primary impact of successful exploitation is a denial-of-service condition affecting system availability, though minor impacts to confidentiality and integrity are also possible according to the CVSS vector. Patches were released in the May 2026 security update.
Affected products
- Huawei HarmonyOS 4.3.1, 4.3.0, 4.2.0, 4.0.0, 3.1.0
- Huawei EMUI 15.0.0, 14.2.0, 14.0.0, 13.0.0
Timeline
- 2026-05-07: other: Advisory updated by vendor
- 2026-05-15: disclosed: NVD publication date