Impact
The vulnerability is a permission control flaw in the notification module of Huawei EMUI and HarmonyOS. It allows an attacker to bypass expected access restrictions, leading to a denial of service that impacts system availability. The weakness is classified as CWE-264, indicating improper privilege management.
Affected Systems
The flaw impacts Huawei's EMUI operating system and HarmonyOS. No specific product versions are listed in the advisory, so all currently deployed firmware versions may be affected until a vendor fix is released.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate severity. EPSS is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting low to moderate promise of exploitation in the wild. The likely attack vector is local, as the notification module typically requires user or privileged access; however the description does not detail whether remote exploitation is possible. Operators should consider that a successful breach of the permission model can disrupt service availability on the device. Remediation depends on vendor updates, but in interim users can isolate notification services if the platform supports it.
OpenCVE Enrichment