Junglewise Threat Intelligence

CVE-2026-41987: Huawei HarmonyOS permission control vulnerability in app management module

CVE-2026-41987 · Severity: medium · CVSS 6.2 · Published 2026-09-09

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

Huawei's HarmonyOS operating system contains a permission control flaw in its app management module that could allow unauthorized access or actions within the app management system. Successful exploitation may disrupt the normal operation and availability of device functionality, affecting phones, tablets, and other Huawei devices running affected HarmonyOS versions.

Technical details

This is a permission control vulnerability (privilege escalation or authorization bypass) in the HarmonyOS app management module. The root cause involves improper validation or enforcement of permissions when accessing app management functions. The vulnerability affects multiple HarmonyOS versions (4.0.0 through 6.1.0) and EMUI versions (14.0.0 through 16.0.0). An attacker with local or limited network access could exploit this to bypass permission restrictions. Successful exploitation may impact system availability or allow unauthorized app management operations. Huawei has issued patches as part of monthly security updates released in September 2026.

Affected products

  • Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1, 4.3.3, 6.1.0
  • Huawei EMUI 14.0.0, 14.2.0, 15.0.0, 16.0.0

Timeline

  • 2026-09-09: disclosed: CVE-2026-41987 publicly disclosed
  • 2026-09: patched: Security patches included in September 2026 monthly updates

References

Related threats