Description
UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-08-17
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the time and time zone module of HarmonyOS. If an attacker succeeds in exploiting the flaw, the device may crash or reboot, resulting in a denial of service for the user. The weakness is identified as CWE‑416, a memory corruption issue where freed memory is accessed. The primary impact is the loss of availability for the affected device, with no indication of confidentiality or integrity compromise.

Affected Systems

The vulnerability affects Huawei HarmonyOS across all supported device categories, including smartphones, laptops, vision displays and wearables. No specific firmware versions are listed in the advisory.

Risk and Exploitability

The CVSS score is 3.3, indicating a low severity impact. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. When a use‑after‑free can be triggered through ordinary module usage, the attack vector may involve either local or remote exploitation depending on how the device is exposed. The overall risk is low, yet the available-defined device crashes and reboots warranted an advisory.

Generated by OpenCVE AI on August 17, 2026 at 11:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HarmonyOS firmware to the latest vendor release that patches the memory‑corruption flaw
  • If an update is not yet available, disable or restrict access to the time and time zone module to mitigate potential crashes
  • Monitor device logs for abnormal reboots or crashes and plan for a timely update once the patch is released

Generated by OpenCVE AI on August 17, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in HarmonyOS Time Module Can Crash Devices

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-17T11:06:17.628Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49306

cve-icon Vulnrichment

Updated: 2026-08-17T11:06:13.894Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:30.730

Modified: 2026-08-26T16:33:17.117

Link: CVE-2026-49306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:30:05Z

Weaknesses