Huawei Harmonyos
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Huawei Harmonyos.
By the Year
In 2026 there have been 72 vulnerabilities in Huawei Harmonyos with an average score of 6.0 out of ten. Last year, in 2025 Harmonyos had 189 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Harmonyos in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.22
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 72 | 5.96 |
| 2025 | 189 | 6.18 |
| 2024 | 187 | 6.55 |
| 2023 | 197 | 7.54 |
| 2022 | 257 | 7.54 |
| 2021 | 118 | 7.21 |
It may take a day or so for new Harmonyos vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Huawei Harmonyos Security Vulnerabilities
Huawei OOB Write in WEB Module (CVE-2026-34866)
CVE-2026-34866
5.1 - Medium
- April 13, 2026
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Classic Buffer Overflow
Huawei WEB Module OOB Write CVE-2026-34865
CVE-2026-34865
- April 13, 2026
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Heap-based Buffer Overflow
Boundary-UNL Vulnerability in Huawei App Read Module
CVE-2026-34864
6.8 - Medium
- April 13, 2026
Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.
Buffer Overflow
Huawei FS OOB Write, Availability Impact
CVE-2026-34863
6.7 - Medium
- April 13, 2026
Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.
Memory Corruption
Race Condition in Huawei Power Consumption Stats Module
CVE-2026-34862
6.3 - Medium
- April 13, 2026
Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei Thermal Management Module Race Condition Causing DoS
CVE-2026-34861
6.3 - Medium
- April 13, 2026
Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei Kernel Module UAF (CVE-2026-34859)
CVE-2026-34859
5.9 - Medium
- April 13, 2026
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Dangling pointer
Huawei UAF in Communication Module (CVE-2026-34858)
CVE-2026-34858
4.1 - Medium
- April 13, 2026
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei UAF in Comm Module
CVE-2026-34857
4.7 - Medium
- April 13, 2026
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
OOB Write in Huawei Kernel Module Enables DoS & Data Leak
CVE-2026-34855
5.7 - Medium
- April 13, 2026
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Improper Input Validation
Huawei kernel module UAF vulnerability
CVE-2026-34854
5.7 - Medium
- April 13, 2026
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Dangling pointer
Huawei Screen Manager UAF Causing Availability Impact
CVE-2026-34849
2.5 - Low
- April 13, 2026
UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Use-After-Free in Huawei Communication Module
CVE-2026-34856
7.3 - High
- April 13, 2026
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei LBS Perm Bypass (CVE-2026-34853)
CVE-2026-34853
7.7 - High
- April 13, 2026
Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.
Privilege Context Switching Error
Improper Permission Control in Huawei Theme Setting Module
CVE-2026-28553
6.9 - Medium
- April 13, 2026
Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission Issues
Huawei EMUI Multi-Mode Input System Double-Free Vulnerability
CVE-2026-34867
5.6 - Medium
- April 13, 2026
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
Double-free
Access Control Bypass in Huawei Memo Module
CVE-2026-34860
4.1 - Medium
- April 13, 2026
Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Authorization
Stack overflow in Huawei MediaPlatform Component leads to DoS
CVE-2026-34852
6.1 - Medium
- April 13, 2026
Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.
Infinite Loop
Huawei Event Notification Module Race Condition (CVE-2026-34851)
CVE-2026-34851
2.2 - Low
- April 13, 2026
Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Race Condition in Huawei Notification Service (CVE-2026-34850)
CVE-2026-34850
1.9 - Low
- April 13, 2026
Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei HarmonyOS SysService Framework Permission Bypass
CVE-2026-28542
7.3 - High
- March 05, 2026
Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
Improper Handling of Exceptional Conditions
Huawei Email App Improper Verification may Expose Service Confidential
CVE-2026-28548
7.1 - High
- March 05, 2026
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Improper Privilege Management
Huawei Device Security Mgmt Module Race Condition
CVE-2026-28551
4.7 - Medium
- March 05, 2026
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Race condition in Huawei permission management service (CVE-2026-28549)
CVE-2026-28549
6.6 - Medium
- March 05, 2026
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Uninitialized Pointer Access in Huawei Scanning Module Causing DoS
CVE-2026-28547
6.8 - Medium
- March 05, 2026
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
Access of Uninitialized Pointer
Huawei Scanning Module Buffer Overflow (CVE-2026-28546)
CVE-2026-28546
5.9 - Medium
- March 05, 2026
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
Heap-based Buffer Overflow
Huawei MaintnDiag Module Race Condition Affects Availability
CVE-2026-28543
4.4 - Medium
- March 05, 2026
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei HarmonyOS Cellular_Data Permission Issue (CVE-2026-28541)
CVE-2026-28541
4 - Medium
- March 05, 2026
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
Permissions, Privileges, and Access Controls
Huawei Bluetooth OOB Char Read CVE-2026-28540
CVE-2026-28540
4 - Medium
- March 05, 2026
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Improper Neutralization of Null Byte or NUL Character
Huawei CVE-2026-28539: Data Processing Vulnerability in Cert Management Mod
CVE-2026-28539
6.2 - Medium
- March 05, 2026
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Data Processing Errors
Huawei CertMgr Path Traversal Vulnerability
CVE-2026-28538
5.9 - Medium
- March 05, 2026
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
Path Traversal: '../filedir'
Huawei Cloud Resource Scheduler Permission Control Flaw
CVE-2025-66319
3.3 - Low
- March 05, 2026
Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.
Permissions, Privileges, and Access Controls
Huawei IMS Module OOB Write Availability Impact
CVE-2026-28552
6.5 - Medium
- March 05, 2026
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
Data Processing Errors
Race Condition in Huawei Security Control Module
CVE-2026-28550
4 - Medium
- March 05, 2026
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
Business Logic Errors
Race Condition in Huawei Printing Module Causing DoS
CVE-2026-28545
5.9 - Medium
- March 05, 2026
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei Printing Module Race Condition (CVE-2026-28544)
CVE-2026-28544
6.2 - Medium
- March 05, 2026
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
Huawei HarmonyOS Double-free in Window Module
CVE-2026-28537
5.1 - Medium
- March 05, 2026
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.
Double-free
Authentication Bypass in Huawei Device Auth Module
CVE-2026-28536
9.6 - Critical
- March 05, 2026
Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Authentication Bypass by Primary Weakness
OOB Write in File System Module CVE-2026-24928
CVE-2026-24928
5.8 - Medium
- February 06, 2026
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Integer Overflow to Buffer Overflow
CVE-2026-24927: OOB Access in FM Mod Module Availability Risk
CVE-2026-24927
5.5 - Medium
- February 06, 2026
Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.
Dangling pointer
Improper Permission Control in Print Module Exposes Service Confidentiality
CVE-2026-24924
6.1 - Medium
- February 06, 2026
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permissions, Privileges, and Access Controls
Permission Control Vulnerability in AMS Module
CVE-2026-24920
6.2 - Medium
- February 06, 2026
Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.
Permissions, Privileges, and Access Controls
DFX Module OOB Write Vulnerability
CVE-2026-24919
6 - Medium
- February 06, 2026
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.
Memory Corruption
UAF in Security Module via CVE-2026-24917
CVE-2026-24917
6.5 - Medium
- February 06, 2026
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
Dangling pointer
CVE-2026-24916 Auth Bypass in Window Module
CVE-2026-24916
5.9 - Medium
- February 06, 2026
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Information Disclosure
Card Module Improper Security Check CVE-2026-24931
CVE-2026-24931
5.9 - Medium
- February 06, 2026
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permissions, Privileges, and Access Controls
UAF Concurrency Vulnerability in Graphics Module
CVE-2026-24930
8.4 - High
- February 06, 2026
UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Race Condition
OOB read in graphics module leads to potential DoS
CVE-2026-24929
5.9 - Medium
- February 06, 2026
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
NULL Pointer Dereference
HDC module permission control flaw compromises confidentiality
CVE-2026-24923
6.3 - Medium
- February 06, 2026
Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permissions, Privileges, and Access Controls
Buffer Overflow in HDC Module (CVE-2026-24922)
CVE-2026-24922
6.9 - Medium
- February 06, 2026
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.
Heap-based Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Huawei Harmonyos or by Huawei? Click the Watch button to subscribe.