Executive brief
A denial-of-service vulnerability exists in the vibration service of Huawei mobile devices. This component manages haptic feedback and vibration alerts for the operating system. A successful exploit could cause the service to crash or become unresponsive, impacting the device's ability to provide physical notifications to the user.
Technical details
A denial-of-service (DoS) vulnerability exists in the vibration service of Huawei HarmonyOS and EMUI. The flaw is categorized as CWE-789 (Memory Allocation with Excessive Size Value), suggesting that the service fails to properly validate the size of memory allocation requests. An attacker can exploit this over the network, though user interaction is required (UI:R), to trigger an out-of-memory condition or service crash. This results in a loss of availability for the vibration functionality. Patches were released as part of the Huawei July 2026 security bulletin.
Affected products
- Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, 4.3.1
- Huawei EMUI 14.0.0, 14.2.0, 15.0.0
Timeline
- 2026-07-08: advisory: Initial Huawei security bulletin published
- 2026-07-15: disclosed: NVD publication date