Security Bulletins for HUAWEI Phones/Tablets, June 2026
HUAWEI is releasing monthly security updates for flagship models. This security update includes HUAWEI and third-party library patches:
This security update includes the following HUAWEI patches:
| CVE | Vulnerability Description | Impact | Severity | Affected Version |
|---|---|---|---|---|
| CVE-2026-41972 | Path traversal vulnerability in the SMS app | Successful exploitation of this vulnerability may affect availability. | High | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-41973 | Permission control vulnerability in calls | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2026-41974 | Permission control vulnerability in service notifications | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2026-41975 | Permission management vulnerability in the network management module | Successful exploitation of this vulnerability may affect service integrity. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0 |
| CVE-2026-41976 | Permission control vulnerability in the audio framework | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS4.3.1, HarmonyOS4.3.0, EMUI 15.0.0 |
| CVE-2026-41977 | DoS vulnerability in the log service | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2026-41979 | Permission control vulnerability in the print module | Successful exploitation of this vulnerability may affect integrity and confidentiality. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0 |
| CVE-2026-41980 | Permission control vulnerability in the file preview module | Successful exploitation of this vulnerability may affect service confidentiality. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0 |
| CVE-2026-41981 | Out-of-bounds write vulnerability in the IPC module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-41982 | Race condition vulnerability in the IPC module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-41983 | DoS vulnerability in the browser kernel | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0 |
| CVE-2026-41984 | UAF vulnerability in the package management module | Successful exploitation of this vulnerability may affect service integrity. | Medium | HarmonyOS6.1.0 |
| CVE-2026-41985 | UAF vulnerability in the package management module | Successful exploitation of this vulnerability may affect service integrity. | Medium | HarmonyOS6.1.0 |
| CVE-2026-41986 | Logic bypass vulnerability in the file system | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
This security update includes the following third-party library patches:
| CVE | Severity | Affected Version |
|---|---|---|
| CVE-2026-0073 | Critical | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2025-57052 | Critical | HarmonyOS5.1.0 |
| CVE-2026-31789 | Critical | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2025-48544 | High | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2025-48574 | High | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2026-0034 | High | HarmonyOS4.3.1, HarmonyOS4.3.0, HarmonyOS4.2.0, HarmonyOS4.0.0, EMUI 15.0.0, EMUI 14.2.0, EMUI 14.0.0 |
| CVE-2026-6314 | High | HarmonyOS6.1.0, HarmonyOS6.0.0 |
| CVE-2026-28387 | High | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-28388 | High | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-28389 | High | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-28390 | High | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-31790 | High | HarmonyOS6.1.0, HarmonyOS6.0.0, HarmonyOS5.1.0 |
Updated on: 2026-06-05