Impact
The vulnerability is a denial‑of‑service flaw located in the browser kernel of HarmonyOS. Exploiting it can cause the browser component to become unavailable, compromising system availability without affecting confidentiality or integrity. The issue is classified as CWE‑399, indicating a resource exhaustion or kernel crash problem.
Affected Systems
Huawei HarmonyOS is the affected product. No specific OS or device model is mentioned, and no version range is provided. All HarmonyOS installations that include this browser kernel are potentially vulnerable until the vendor issues a fix.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range, and no EPSS score is currently available, suggesting limited known exploitation activity. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves sending malicious input to the browser kernel, which would be effective against local users or remote users who navigate to a malicious site. Because precise attack and privilege prerequisites are not detailed, the exact exploitation path is inferred rather than confirmed.
OpenCVE Enrichment