Harmonyos Huawei Harmonyos

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Huawei Harmonyos.

By the Year

In 2026 there have been 72 vulnerabilities in Huawei Harmonyos with an average score of 6.0 out of ten. Last year, in 2025 Harmonyos had 189 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Harmonyos in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.22




Year Vulnerabilities Average Score
2026 72 5.96
2025 189 6.18
2024 187 6.55
2023 197 7.54
2022 257 7.54
2021 118 7.21

It may take a day or so for new Harmonyos vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Huawei Harmonyos Security Vulnerabilities

Huawei OOB Write in WEB Module (CVE-2026-34866)
CVE-2026-34866 5.1 - Medium - April 13, 2026

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Classic Buffer Overflow

Huawei WEB Module OOB Write CVE-2026-34865
CVE-2026-34865 - April 13, 2026

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Heap-based Buffer Overflow

Boundary-UNL Vulnerability in Huawei App Read Module
CVE-2026-34864 6.8 - Medium - April 13, 2026

Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.

Buffer Overflow

Huawei FS OOB Write, Availability Impact
CVE-2026-34863 6.7 - Medium - April 13, 2026

Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

Memory Corruption

Race Condition in Huawei Power Consumption Stats Module
CVE-2026-34862 6.3 - Medium - April 13, 2026

Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei Thermal Management Module Race Condition Causing DoS
CVE-2026-34861 6.3 - Medium - April 13, 2026

Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei Kernel Module UAF (CVE-2026-34859)
CVE-2026-34859 5.9 - Medium - April 13, 2026

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Dangling pointer

Huawei UAF in Communication Module (CVE-2026-34858)
CVE-2026-34858 4.1 - Medium - April 13, 2026

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei UAF in Comm Module
CVE-2026-34857 4.7 - Medium - April 13, 2026

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

OOB Write in Huawei Kernel Module Enables DoS & Data Leak
CVE-2026-34855 5.7 - Medium - April 13, 2026

Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Improper Input Validation

Huawei kernel module UAF vulnerability
CVE-2026-34854 5.7 - Medium - April 13, 2026

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Dangling pointer

Huawei Screen Manager UAF Causing Availability Impact
CVE-2026-34849 2.5 - Low - April 13, 2026

UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Use-After-Free in Huawei Communication Module
CVE-2026-34856 7.3 - High - April 13, 2026

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei LBS Perm Bypass (CVE-2026-34853)
CVE-2026-34853 7.7 - High - April 13, 2026

Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.

Privilege Context Switching Error

Improper Permission Control in Huawei Theme Setting Module
CVE-2026-28553 6.9 - Medium - April 13, 2026

Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Permission Issues

Huawei EMUI Multi-Mode Input System Double-Free Vulnerability
CVE-2026-34867 5.6 - Medium - April 13, 2026

Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.

Double-free

Access Control Bypass in Huawei Memo Module
CVE-2026-34860 4.1 - Medium - April 13, 2026

Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Authorization

Stack overflow in Huawei MediaPlatform Component leads to DoS
CVE-2026-34852 6.1 - Medium - April 13, 2026

Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.

Infinite Loop

Huawei Event Notification Module Race Condition (CVE-2026-34851)
CVE-2026-34851 2.2 - Low - April 13, 2026

Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Race Condition in Huawei Notification Service (CVE-2026-34850)
CVE-2026-34850 1.9 - Low - April 13, 2026

Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei HarmonyOS SysService Framework Permission Bypass
CVE-2026-28542 7.3 - High - March 05, 2026

Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.

Improper Handling of Exceptional Conditions

Huawei Email App Improper Verification may Expose Service Confidential
CVE-2026-28548 7.1 - High - March 05, 2026

Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Improper Privilege Management

Huawei Device Security Mgmt Module Race Condition
CVE-2026-28551 4.7 - Medium - March 05, 2026

Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Race condition in Huawei permission management service (CVE-2026-28549)
CVE-2026-28549 6.6 - Medium - March 05, 2026

Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Uninitialized Pointer Access in Huawei Scanning Module Causing DoS
CVE-2026-28547 6.8 - Medium - March 05, 2026

Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

Access of Uninitialized Pointer

Huawei Scanning Module Buffer Overflow (CVE-2026-28546)
CVE-2026-28546 5.9 - Medium - March 05, 2026

Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

Heap-based Buffer Overflow

Huawei MaintnDiag Module Race Condition Affects Availability
CVE-2026-28543 4.4 - Medium - March 05, 2026

Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei HarmonyOS Cellular_Data Permission Issue (CVE-2026-28541)
CVE-2026-28541 4 - Medium - March 05, 2026

Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.

Permissions, Privileges, and Access Controls

Huawei Bluetooth OOB Char Read CVE-2026-28540
CVE-2026-28540 4 - Medium - March 05, 2026

Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Improper Neutralization of Null Byte or NUL Character

Huawei CVE-2026-28539: Data Processing Vulnerability in Cert Management Mod
CVE-2026-28539 6.2 - Medium - March 05, 2026

Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Data Processing Errors

Huawei CertMgr Path Traversal Vulnerability
CVE-2026-28538 5.9 - Medium - March 05, 2026

Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.

Path Traversal: '../filedir'

Huawei Cloud Resource Scheduler Permission Control Flaw
CVE-2025-66319 3.3 - Low - March 05, 2026

Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Permissions, Privileges, and Access Controls

Huawei IMS Module OOB Write Availability Impact
CVE-2026-28552 6.5 - Medium - March 05, 2026

Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.

Data Processing Errors

Race Condition in Huawei Security Control Module
CVE-2026-28550 4 - Medium - March 05, 2026

Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

Business Logic Errors

Race Condition in Huawei Printing Module Causing DoS
CVE-2026-28545 5.9 - Medium - March 05, 2026

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei Printing Module Race Condition (CVE-2026-28544)
CVE-2026-28544 6.2 - Medium - March 05, 2026

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

Huawei HarmonyOS Double-free in Window Module
CVE-2026-28537 5.1 - Medium - March 05, 2026

Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.

Double-free

Authentication Bypass in Huawei Device Auth Module
CVE-2026-28536 9.6 - Critical - March 05, 2026

Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Authentication Bypass by Primary Weakness

OOB Write in File System Module CVE-2026-24928
CVE-2026-24928 5.8 - Medium - February 06, 2026

Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Integer Overflow to Buffer Overflow

CVE-2026-24927: OOB Access in FM Mod Module Availability Risk
CVE-2026-24927 5.5 - Medium - February 06, 2026

Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.

Dangling pointer

Improper Permission Control in Print Module Exposes Service Confidentiality
CVE-2026-24924 6.1 - Medium - February 06, 2026

Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Permissions, Privileges, and Access Controls

Permission Control Vulnerability in AMS Module
CVE-2026-24920 6.2 - Medium - February 06, 2026

Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.

Permissions, Privileges, and Access Controls

DFX Module OOB Write Vulnerability
CVE-2026-24919 6 - Medium - February 06, 2026

Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.

Memory Corruption

UAF in Security Module via CVE-2026-24917
CVE-2026-24917 6.5 - Medium - February 06, 2026

UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.

Dangling pointer

CVE-2026-24916 Auth Bypass in Window Module
CVE-2026-24916 5.9 - Medium - February 06, 2026

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Information Disclosure

Card Module Improper Security Check CVE-2026-24931
CVE-2026-24931 5.9 - Medium - February 06, 2026

Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Permissions, Privileges, and Access Controls

UAF Concurrency Vulnerability in Graphics Module
CVE-2026-24930 8.4 - High - February 06, 2026

UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

Race Condition

OOB read in graphics module leads to potential DoS
CVE-2026-24929 5.9 - Medium - February 06, 2026

Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

NULL Pointer Dereference

HDC module permission control flaw compromises confidentiality
CVE-2026-24923 6.3 - Medium - February 06, 2026

Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Permissions, Privileges, and Access Controls

Buffer Overflow in HDC Module (CVE-2026-24922)
CVE-2026-24922 6.9 - Medium - February 06, 2026

Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.

Heap-based Buffer Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Huawei Harmonyos or by Huawei? Click the Watch button to subscribe.

Huawei
Vendor

subscribe