Executive brief
A security vulnerability exists in the service notification system of Huawei smartphones, tablets, and Vision devices. This flaw could allow an attacker to interfere with the normal operation of the device's notification services, potentially leading to service disruptions or reduced availability for the user. Users are advised to update their devices to the latest HarmonyOS or EMUI versions released in June 2026 to resolve this issue.
Technical details
A permission control vulnerability (CWE-264) exists in the service notification component of Huawei's HarmonyOS and EMUI. The vulnerability is triggered locally and requires user interaction, as indicated by the CVSS vector (AV:L/UI:R). Successful exploitation allows an attacker to bypass intended access controls, which can lead to a localized denial-of-service or otherwise impact the availability of notification services. The issue affects HarmonyOS versions 4.0.0 through 4.3.1 and EMUI versions 14.0.0 through 15.0.0. Huawei has released patches as part of the June 2026 security bulletin.
Affected products
- Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1
- Huawei EMUI 14.0.0, 14.2.0, 15.0.0
Timeline
- 2026-06-05: patched: Huawei released security bulletin details.
- 2026-06-09: disclosed: CVE published to NVD.