Impact
The OOB write vulnerability occurs in the rendering and composition module of HarmonyOS. An attacker who can manipulate graphics rendering input could corrupt memory, leading to a crash that disrupts the operating system’s ability to display user interfaces and could cause a denial‑of‑service condition. The flaw is a classic out‑of‑bounds write (CWE‑125), which allows an attacker to overwrite adjacent memory and potentially subvert the normal control flow of the rendering engine.
Affected Systems
The affected systems are devices running Huawei HarmonyOS. The vulnerability was identified in the rendering and composition module of that operating system; vendor‑level version information is not specified, so all releases of HarmonyOS that include the affected module should be treated as vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting there are no confirmed exploitation campaigns. The attack vector is likely local or remote if an attacker can supply malicious graphics data, so any edge case where untrusted input is processed by the rendering subsystem poses a risk. Without a publicly documented patch, organizations should prepare to apply official updates as soon as they become available.
OpenCVE Enrichment