Junglewise Threat Intelligence

CVE-2026-49313: Huawei HarmonyOS permission control vulnerability in app lock module

CVE-2026-49313 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A permission control flaw in Huawei's HarmonyOS operating system affects the app lock module, which users rely on to secure sensitive applications. An attacker could exploit this vulnerability to bypass permission restrictions and access confidential information stored in locked apps or related system settings.

Technical details

This vulnerability is a permission control bypass in the app lock module of HarmonyOS 6.1.0. The vulnerability allows an attacker to circumvent permission checks that normally protect app-locking features. The attack vector and specific preconditions are not detailed in the advisory, but successful exploitation results in unauthorized access to service confidentiality. Huawei released patches in September 2026 as part of their monthly security update cycle.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-05: patched: Patch released in September 2026 security update

References

Related threats