Executive brief
A security vulnerability exists in the Inter-Process Communication (IPC) module of Huawei HarmonyOS, which is used by smartphones, tablets, and smartwatches to manage data exchange between different applications. An attacker with local access to the device could exploit this flaw to cause system instability or a service outage. This could result in the device becoming unresponsive or requiring a restart, impacting the user's ability to use their device and its applications.
Technical details
An out-of-bounds write vulnerability (CWE-122) exists in the Inter-Process Communication (IPC) module of Huawei HarmonyOS. The flaw is rooted in a heap-based buffer overflow where the system fails to properly validate the boundaries of data being written to memory. A local attacker with low privileges can exploit this vulnerability without user interaction to trigger a crash or potentially execute arbitrary code, though the primary reported impact is on system availability. The vulnerability affects HarmonyOS versions 5.1.0, 6.0.0, and 6.1.0. Huawei has released security patches as part of the June 2026 security bulletin.
Affected products
- Huawei HarmonyOS 5.1.0, 6.0.0, 6.1.0
Timeline
- 2026-06-05: patched: Huawei released security bulletin updates.
- 2026-06-09: disclosed: NVD published the CVE record.