Impact
Null pointer dereference vulnerability exists in the browser module of HarmonyOS, causing an indirect crash of the browser kernel and leading to an availability loss. Exploiting this flaw can render the browser component unusable, compromising system availability while not impacting data confidentiality or integrity. The flaw is categorized as CWE-399, signifying a resource exhaustion or kernel crash issue.
Affected Systems
Huawei HarmonyOS is the affected product. No specific OS or device model is mentioned, and no version range is provided. All HarmonyOS installations that include this browser kernel are potentially vulnerable until the vendor issues a fix.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range, and the EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves sending malicious input to the browser kernel, which would be effective against local users or remote users who navigate to a malicious site. Because precise attack and privilege prerequisites are not detailed, the exact exploitation path is inferred rather than confirmed.
OpenCVE Enrichment