Impact
The vulnerability is a permission control flaw in the event notification module of Huawei HarmonyOS. An attacker who successfully exploits it may gain unauthorized access to event data, allowing them to read confidential information that the system disseminates. This could lead to leakage of user data, system configuration, or communication events, thereby compromising the confidentiality of services running on the device.
Affected Systems
The flaw affects Huawei HarmonyOS across devices such as smartphones, laptops, vision devices, and wearables. The exact affected versions are not enumerated in the data, so any HarmonyOS build present during the September 2026 bulletin is potentially impacted.
Risk and Exploitability
The vulnerability carries a high CVSS score of 8.6 and is not listed in the CISA KEV catalog. The EPSS score is not available, indicating no publicly reported exploitation data. The likely attack vector is a local or remote exploitation through crafted event notifications, though the precise conditions are not detailed in the description. Given the high severity and lack of known mitigation, the risk to confidentiality remains significant.
OpenCVE Enrichment