Executive brief
A denial-of-service vulnerability exists in the browser kernel of Huawei HarmonyOS devices, including smartphones, tablets, PCs, and smartwatches. An attacker could exploit this flaw to cause the browser or system components to crash or become unresponsive, disrupting the user's ability to access web services or use the device. This issue primarily impacts the availability of the device's web-related functions.
Technical details
A denial-of-service (DoS) vulnerability exists in the browser kernel of Huawei HarmonyOS. The flaw is categorized under CWE-399 (Resource Management Errors), suggesting that improper handling of system resources can lead to a crash or exhaustion. The attack vector is network-based and requires user interaction (UI:R), typically involving a user visiting a malicious webpage. Successful exploitation allows an unauthenticated remote attacker to impact the availability of the affected component. The vulnerability affects HarmonyOS versions 6.0.0 and 6.1.0 across multiple device categories. Patches were released as part of the June 2026 security update.
Affected products
- Huawei HarmonyOS 6.0.0, 6.1.0
Timeline
- 2026-06-05: patched: Huawei released security bulletins for phones, tablets, PCs, and wearables.
- 2026-06-09: disclosed: CVE published in the National Vulnerability Database.