Executive brief
HarmonyOS is the operating system powering Huawei phones, tablets, and PCs. A permission control flaw in the event notification module allows unauthorized access to sensitive notification data, potentially exposing user information. An attacker with local access could bypass security controls to read confidential service data without proper authorization.
Technical details
This is a permission control vulnerability (improper access control) in the event notification module of HarmonyOS. The vulnerability allows an attacker with local access to bypass permission checks and access sensitive notification data, affecting service confidentiality. The flaw resides in the notification handling component which fails to properly validate user permissions before exposing event data. Exploitation requires local access to the device and does not require user interaction. The vulnerability affects HarmonyOS 6.1.0, and patches are available via official security updates released in September 2026.
Affected products
- Huawei HarmonyOS 6.1.0
Timeline
- 2026-09-09: disclosed
- 2026-09-05: patched: Security update released