Impact
A use‑after‑free flaw exists in the time and time zone module of HarmonyOS. If an attacker succeeds in exploiting the flaw, the device may crash or reboot, resulting in a denial of service for the user. The weakness is identified as CWE‑416, a memory corruption issue where freed memory is accessed. The primary impact is the loss of availability for the affected device, with no indication of confidentiality or integrity compromise.
Affected Systems
The vulnerability affects Huawei HarmonyOS across all supported device categories, including smartphones, laptops, vision displays and wearables. No specific firmware versions are listed in the advisory.
Risk and Exploitability
The CVSS score is 3.3, indicating a low severity impact. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. When a use‑after‑free can be triggered through ordinary module usage, the attack vector may involve either local or remote exploitation depending on how the device is exposed. The overall risk is low, yet the available-defined device crashes and reboots warranted an advisory.
OpenCVE Enrichment