Executive brief
A security flaw has been identified in the 'clone' module of Huawei HarmonyOS, which is used on laptops and other smart devices. This vulnerability could allow an unauthorized person or malicious application to bypass intended access restrictions. If exploited, it could lead to the exposure of private user data or sensitive system information.
Technical details
A permission control vulnerability (CWE-275) exists in the clone module of Huawei HarmonyOS versions 6.0.0 and 6.1.0. The flaw stems from improper enforcement of access rights within the module, which is reachable via local attack vectors. Exploitation requires user interaction (UI:R) and can result in a loss of confidentiality and a minor impact on availability. Attackers could potentially leverage this to access data they are not authorized to view. Huawei has addressed this issue in the June 2026 security update for HUAWEI PCs.
Affected products
- Huawei HarmonyOS 6.0.0, 6.1.0
Timeline
- 2026-06-05: patched: Huawei released security bulletin for HUAWEI PCs
- 2026-06-09: disclosed: NVD publication date