Impact
The reported defect is an out-of-bounds read (CWE-120) in the image codec module of HarmonyOS. This flaw allows an attacker to read arbitrary memory locations when the codec processes crafted image data, potentially leaking confidential information. The vulnerability does not provide a path to modify data or execute code; the impact is limited to the disclosure of data that resides in adjacent memory.
Affected Systems
The affected product is the HarmonyOS operating system, distributed by Huawei across consumer devices such as smartphones, laptops, vision devices, and wearables. No specific version numbers are included in the advisory, so all installations that use the vulnerable codec implementation should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 4 ranks the flaw as low to moderate severity. An EPSS score of less than 1% indicates that exploitation of the vulnerability is unlikely in the wild at this time, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local file input or network transmission of a crafted image that is decoded by the system. The lack of a mention of remote execution or privilege escalation suggests that only devices that can provide the vulnerable data will be affected, making exploitation more constrained.
OpenCVE Enrichment