Executive brief
A security vulnerability exists in the print module of Huawei HarmonyOS, which is used by smartphones, tablets, and laptops to manage printing tasks. If exploited, this flaw could allow an attacker to compromise the integrity and confidentiality of system data. This could lead to unauthorized changes to files or the exposure of sensitive information handled by the printing service.
Technical details
A permission control vulnerability (CWE-701) exists in the print module of Huawei HarmonyOS versions 6.0.0 and 6.1.0. The flaw stems from improper design-level enforcement of access controls within the printing component. An attacker can exploit this locally, though it requires user interaction (UI:R), to bypass intended restrictions. Successful exploitation allows the attacker to impact the integrity and confidentiality of the system, potentially modifying or accessing data they should not have permission to reach. Huawei has addressed this in the June 2026 security update.
Affected products
- Huawei HarmonyOS 6.0.0, 6.1.0
Timeline
- 2026-06-05: advisory: Huawei published the security bulletin.
- 2026-06-09: disclosed: CVE published to the NVD.