Junglewise Threat Intelligence

CVE-2026-41980: Huawei HarmonyOS permission control vulnerability in file preview module

CVE-2026-41980 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability has been identified in the file preview module of Huawei HarmonyOS, which is used on smartphones, tablets, and PCs to view documents and media without opening full applications. If exploited, this flaw could allow unauthorized access to sensitive information stored on the device. This could lead to a breach of user privacy or the exposure of confidential personal and business files.

Technical details

A permission control vulnerability (CWE-200) exists in the file preview module of Huawei HarmonyOS versions 6.0.0 and 6.1.0. The flaw stems from improper enforcement of access controls within the component responsible for generating file previews. An attacker can exploit this via a local attack vector, though it requires user interaction (UI:R) to succeed. Successful exploitation allows an unauthorized actor to bypass intended restrictions and gain access to sensitive data, impacting the confidentiality of the service. Huawei has addressed this issue in the June 2026 security update.

Affected products

  • Huawei HarmonyOS 6.0.0, 6.1.0

Timeline

  • 2026-06-05: patched: Huawei released security bulletins for phones, tablets, PCs, and Vision products.
  • 2026-06-09: disclosed: NVD published the CVE record.

References

Related threats