Junglewise Threat Intelligence

CVE-2026-41973: Huawei HarmonyOS and EMUI permission control vulnerability in calls

CVE-2026-41973 · Severity: medium · CVSS 5.9 · Published 2026-06-09

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security flaw has been identified in the calling functionality of Huawei mobile devices. This vulnerability could allow an unauthorized party to interfere with the phone's ability to handle calls, potentially leading to service disruptions. This impact on availability could prevent users from making or receiving important communications.

Technical details

A permission control vulnerability exists in the 'calls' component of Huawei's HarmonyOS and EMUI. Categorized as a business logic error (CWE-840), the flaw allows for improper enforcement of access controls. An attacker with local access could exploit this to impact the availability, confidentiality, or integrity of the calling service. The vulnerability is addressed in the June 2026 security update for affected flagship models.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0

Timeline

  • 2026-06-05: advisory: Huawei published the security bulletin.
  • 2026-06-09: disclosed: NVD published the CVE record.

References

Related threats