Executive brief
A security vulnerability has been identified in the SMS application on Huawei HarmonyOS devices. This flaw could allow an attacker to interfere with the application's normal operation, potentially leading to service disruptions or making the messaging app unavailable to the user. This could impact a user's ability to send or receive critical communications.
Technical details
A path traversal vulnerability (CWE-22) exists in the SMS application of Huawei HarmonyOS. The vulnerability stems from improper limitation of a pathname to a restricted directory, which can be exploited over the network. While the specific mechanism is not detailed, the CVSS vector indicates that user interaction is required (UI:R). Successful exploitation primarily impacts the availability of the SMS service. The issue affects HarmonyOS versions 5.1.0, 6.0.0, and 6.1.0, and was addressed in the June 2026 security update.
Affected products
- Huawei HarmonyOS 6.1.0, 6.0.0, 5.1.0
Timeline
- 2026-06-05: advisory: Huawei published the security bulletin.
- 2026-06-09: disclosed: NVD published the CVE record.