Executive brief
A security vulnerability exists in the package management module of Huawei HarmonyOS, which is used to handle application installations and updates on smartphones, tablets, and smartwatches. If exploited, this flaw could allow an attacker to compromise the integrity of the system services. This could lead to unauthorized changes to system software or instability in how the device manages applications.
Technical details
A Use-After-Free (UAF) vulnerability exists within the package management module of Huawei HarmonyOS 6.1.0. The flaw is categorized under improper access control (CWE-284). According to the CVSS vector, exploitation requires high privileges, a high degree of complexity, and user interaction on the local system. Successful exploitation allows an attacker to impact service integrity, with minor impacts on confidentiality and availability. Huawei has addressed this vulnerability in its June 2026 security update across affected mobile, PC, and wearable platforms.
Affected products
- Huawei HarmonyOS 6.1.0
Timeline
- 2026-06-05: patched: Huawei released security bulletins for June 2026 addressing the issue.
- 2026-06-09: disclosed: NVD published the CVE record.