Huawei HarmonyOS UAF Vulnerability in Kernel Module Allowing Confidentiality and Availability Impact

Vulnerability

A use-after-free vulnerability has been identified in the kernel module of Huawei's HarmonyOS. This vulnerability affects several versions, including HarmonyOS 6.0.0, HarmonyOS 5.1.0, HarmonyOS 4.3.1, HarmonyOS 4.3.0, HarmonyOS 4.2.0, HarmonyOS 4.0.0, EMUI 15.0.0, EMUI 14.2.0, and EMUI 14.0.0. Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information and disrupt normal system operations.

Impact

Exploitation of this vulnerability could cause a use-after-free condition, potentially leading to memory corruption. This type of vulnerability can often be exploited to execute arbitrary code or cause a denial-of-service condition, where the system becomes unresponsive or unavailable.

Added: Apr 13, 2026, 5:25 AM
Updated: Apr 13, 2026, 5:25 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
3.3
remediation
7.7
relevance
5.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.