Impact
This vulnerability is an out‑of‑bounds read in the media subsystem of Huawei HarmonyOS. A maliciously crafted media file can cause the system to read beyond the boundaries of a buffer, potentially leaking sensitive data and leading to a local crash. Consequently, attackers may obtain confidential information or cause a denial of service by terminating media playback or related services.
Affected Systems
The affected vendor is Huawei and the product is HarmonyOS. All publicly disclosed versions that meet the impact criteria—5.1.0, 5.1.1, and 6.0.0—are vulnerable according to the CNAs.
Risk and Exploitability
With a CVSS score of 6.2 and an EPSS probability of less than 1 %, exploitation is considered moderately risky but unlikely at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker would need to supply a malicious media file to the device, which may occur when users play or preview media from untrusted sources. The exploit does not currently provide remote code execution, but it can expose sensitive information and disrupt media functionality.
OpenCVE Enrichment