Impact
A use‑after‑free flaw exists in the package management module of Huawei HarmonyOS. This vulnerability allows an attacker to manipulate the code path after a memory object has been freed, leading to unauthorized or erroneous modifications to the package installation process. The consequences are loss of service integrity, which could disrupt application functionality or prevent proper package updates.
Affected Systems
Huawei HarmonyOS is affected. The specific OS versions are not listed in the available data, so all current releases may be vulnerable until an official mitigated release is issued.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain. The attack vector is inferred to be local or system‑level, requiring the attacker to interact with the package management service, either through a malicious package or compromised device privileges. Once exploited, the attacker can alter or corrupt installed packages, potentially leading to broader denial of service or integrity compromise.
OpenCVE Enrichment