In January, Huawei patched a bug in its PCManager software, discovered by Microsoft, which acted like NSA-style malware and affected some MateBook laptops
Jon Porter / The Verge :
Context & Ripple Effects
Huawei's January fix closes a hole in PCManager, the bundled management utility on some MateBook laptops, after Microsoft — not Huawei's own team — found the software behaving like NSA-style espionage tooling. The discovery lands on top of an already poor security record: a June 2019 test found 55% of sampled Huawei telecom firmware images carried at least one vulnerability, and researchers later detailed a backdoor in Huawei-owned HiSilicon chips active since 2013.
The episode also echoes an older PC-industry playbook: Lenovo shipped laptops with an anti-theft rootkit that reinstalled unwanted software, forcing a manual optional patch. What is different here is who found the bug — the Windows platform holder auditing its own ecosystem's preinstalled software.
First-order effects
- MateBook owners running PCManager needed the January patch to close a privilege-abuse vector in preinstalled software they did not explicitly install.
- Microsoft's role as discoverer puts Huawei's consumer-laptop software under the same scrutiny its telecom gear already faces from independent testing.
Second-order effects
- Enterprise and government buyers weighing Huawei PCs now have a documented consumer-side incident to stack against the telecom firmware vulnerability findings, raising the effective cost of Huawei's laptop business outside China.
- The find pressures other OEMs whose bundled utilities run with high privileges — the same class of problem flagged when researchers found flaws in kernel drivers from 20 vendors including Intel, AMD, and Huawei.
Third-order effects
- If platform holders like Microsoft keep auditing partner preinstalled software, vendor-bundled utilities shift from a differentiator to a liability, pushing OEMs toward leaner Windows images and third-party code audits.
- A repeated pattern of vendor-shipped software with spyware-like behavior — Lenovo's rootkit, then this — feeds structural distrust of integrated hardware-software vendors and strengthens the case for independent disclosure channels over vendor self-reporting.
The trend: Preinstalled vendor software on PCs is becoming a security battleground, with platform holders and independent researchers — not the OEMs themselves — doing the auditing.