Huawei HarmonyOS and EMUI UAF Vulnerability in USB Driver Module

Vulnerability

A use-after-free vulnerability has been identified in the USB driver module of Huawei's HarmonyOS and EMUI. This vulnerability affects several different versions and ranges of HarmonyOS, as well as EMUI 15.0.0, 14.2.0, 14.0.0, 13.0.0, and 12.0.0. Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information and disruption of service availability.

Impact

Exploitation of this vulnerability could result in a use-after-free condition, potentially leading to memory corruption.

Remediation

Users can refer to the Huawei November 2025 Security Bulletin for guidance on applying the latest security updates.

Added: Nov 28, 2025, 4:22 AM
Updated: Nov 28, 2025, 4:22 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
3.3
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.