Impact
The vulnerability is an out‑of‑bounds write in HarmonyOS’s file system driver. This flaw can corrupt or overwrite critical file system data, potentially leading to system instability or denial of service. The official description notes that successful exploitation may affect availability, which could impede device operation for affected users.
Affected Systems
Huawei HarmonyOS devices are impacted. The CVE does not list affected firmware versions, so administrators should consult Huawei’s consumer support bulletin for specific release information and verify whether their installations contain the vulnerability.
Risk and Exploitability
The CVSS base score of 6.7 indicates a moderate severity vulnerability. No EPSS score is available, and the issue is not cataloged in CISA’s Known Exploited Vulnerabilities list, suggesting limited publicly documented exploitation activity. The exact attack vector is not detailed; based on the description, it is inferred that an attacker must trigger the out‑of‑bounds write, potentially via a malicious file or application, but the official advisory does not disclose the exploit path.
OpenCVE Enrichment