Executive brief
A permission control flaw in Huawei's HarmonyOS operating system affects the app lock module, which users rely on to secure sensitive applications. An attacker could exploit this vulnerability to bypass permission restrictions and access confidential information stored in locked apps or related system settings.
Technical details
This vulnerability is a permission control bypass in the app lock module of HarmonyOS 6.1.0. The vulnerability allows an attacker to circumvent permission checks that normally protect app-locking features. The attack vector and specific preconditions are not detailed in the advisory, but successful exploitation results in unauthorized access to service confidentiality. Huawei released patches in September 2026 as part of their monthly security update cycle.
Affected products
- Huawei HarmonyOS 6.1.0
Timeline
- 2026-09-09: disclosed
- 2026-09-05: patched: Patch released in September 2026 security update