Junglewise Threat Intelligence

CVE-2026-41976: Huawei HarmonyOS and EMUI permission control vulnerability in audio framework

CVE-2026-41976 · Severity: medium · CVSS 6.6 · Published 2026-06-09

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the audio framework of Huawei mobile devices and smart screens. This flaw could allow an attacker to bypass permission controls, potentially leading to the unauthorized access of sensitive audio-related data or services. Exploitation typically requires some form of user interaction on the device.

Technical details

A permission control vulnerability (CWE-275) exists within the Huawei audio framework. The flaw allows for the bypass of intended access restrictions, impacting the confidentiality of the service. The attack vector is local, requiring user interaction (UI:R) to trigger the exploit. Successful exploitation allows an attacker to gain high confidentiality access, with low impacts on integrity and availability. The vulnerability affects HarmonyOS versions 4.3.0 and 4.3.1, as well as EMUI version 15.0.0. Patches were released as part of the June 2026 security update.

Affected products

  • Huawei HarmonyOS 4.3.0, 4.3.1
  • Huawei EMUI 15.0.0

Timeline

  • 2026-06-05: patched: Huawei released security bulletins for June 2026 addressing the issue.
  • 2026-06-09: disclosed: CVE record published and included in NVD dataset.

References

Related threats