Junglewise Threat Intelligence

CVE-2026-41977: Huawei HarmonyOS and EMUI integer overflow in log service

CVE-2026-41977 · Severity: medium · CVSS 5 · Published 2026-06-09

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

A denial-of-service vulnerability exists in the log service of Huawei mobile devices and smart screens. This component is responsible for recording system events and diagnostic information. If exploited, an attacker could cause the log service to crash or become unresponsive, potentially impacting the overall stability and availability of the device.

Technical details

An integer overflow vulnerability (CWE-190) exists in the log service of Huawei's HarmonyOS and EMUI operating systems. The flaw is triggered when the service handles specifically crafted input, leading to a denial-of-service (DoS) condition. According to the CVSS vector, the attack requires local access and user interaction (UI:R), but does not require elevated privileges (PR:N). Successful exploitation allows an attacker to impact the availability of the log service and potentially the wider system. Patches were released as part of the June 2026 security update.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1, 5.1.0, 6.0.0, 6.1.0
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0

Timeline

  • 2026-06-05: patched: Huawei released security bulletins for Phones/Tablets and Vision products.
  • 2026-06-09: disclosed: NVD published the CVE record.

References

Related threats