Security Bulletins for HUAWEI Smart Watches, April 2026
HUAWEI is releasing monthly security updates for flagship models. This security update includes HUAWEI and third-party library patches:
This security update includes the following HUAWEI patches:
| CVE | Vulnerability Description | Impact | Severity | Affected Version |
|---|---|---|---|---|
| CVE-2026-34856 | UAF vulnerability in the communication module | Successful exploitation of this vulnerability may affect availability. | High | HarmonyOS6.0.0 |
| CVE-2026-34852 | Stack overflow vulnerability in the media platform | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.0.0 |
| CVE-2026-34857 | UAF vulnerability in the communication module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-34858 | UAF vulnerability in the communication module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-34861 | Race condition vulnerability in the thermal management module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.0.0 |
| CVE-2026-34862 | Race condition vulnerability in the power consumption statistics module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.0.0 |
| CVE-2026-34864 | Boundary-unlimited vulnerability in the application read module | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS6.0.0 |
| CVE-2026-28549 | Race condition vulnerability in the permission management service | Successful exploitation of this vulnerability may affect availability. | Medium | HarmonyOS5.1.0 |
| CVE-2026-34865 | Out-of-bounds write vulnerability in the WEB module | Successful exploitation of this vulnerability will affect availability and confidentiality. | Medium | HarmonyOS6.0.0 |
| CVE-2026-34866 | Out-of-bounds write vulnerability in the WEB module | Successful exploitation of this vulnerability will affect availability and confidentiality. | Medium | HarmonyOS6.0.0 |
This security update includes the following third-party library patches:
| CVE | Severity | Affected Version |
|---|---|---|
| CVE-2026-0026 | High | HarmonyOS3.1.0, EMUI13.0.0 |
| CVE-2025-38618 | High | HarmonyOS3.1.0, EMUI13.0.0 |
| CVE-2025-48621 | High | HarmonyOS3.1.0, EMUI13.0.0 |
| CVE-2025-48639 | High | HarmonyOS3.1.0, EMUI13.0.0 |
| CVE-2025-9230 | High | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-22693 | Medium | HarmonyOS6.0.0 |
| CVE-2025-28162 | Medium | HarmonyOS6.0.0 |
| CVE-2025-28164 | Medium | HarmonyOS6.0.0 |
| CVE-2026-25646 | Medium | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-0990 | Medium | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-1757 | Medium | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-0989 | Low | HarmonyOS6.0.0, HarmonyOS5.1.0 |
| CVE-2026-0992 | Low | HarmonyOS6.0.0, HarmonyOS5.1.0 |
Updated on: 2026-04-08