Description
Permission control vulnerability in the app lock module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-09-09
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a permission control flaw in the HarmonyOS app lock module. This flaw permits an attacker to bypass lock restrictions and access confidential service information that should be protected by the module.

Affected Systems

It affects Huawei HarmonyOS devices. Specific affected versions are not disclosed, but the problem exists in any build containing the vulnerable app lock module. Users should consult the Huawei support bulletin referenced for update details.

Risk and Exploitability

With a CVSS score of 5.5, the vulnerability represents moderate severity. The EPSS score is unavailable, so the exploitation probability is unknown. The issue is not listed in the CISA KEV catalog, suggesting no known public exploits. The attack vector is not specified; based on the nature of a permission control weakness, potential exploitation could be local or involve elevated privileges.

Generated by OpenCVE AI on September 9, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the Huawei support bulletin at https://consumer.huawei.com/en/support/bulletin/2026/9/ for available patches or updates.
  • If a patch is released, install the updated HarmonyOS firmware to address the permission control flaw.
  • Apply general best practices: restrict app lock permissions, monitor for unauthorized access, and audit the module‑level authorization checks.

Generated by OpenCVE AI on September 9, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Huawei HarmonyOS App Lock Permission Control Vulnerability

Wed, 09 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-09T20:51:32.789Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49313

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:17:59.090

Modified: 2026-09-09T21:17:02.617

Link: CVE-2026-49313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses