Impact
An out-of-bounds read exists in the image codec module, allowing a maliciously crafted image to trigger a read of memory outside the intended buffer. This flaw can leak sensitive data and compromise the confidentiality of the service. The underlying weakness is identified as CWE-120.
Affected Systems
The vulnerability is present in Huawei HarmonyOS devices. No specific product variants or version numbers are documented in the advisory.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves an attacker supplying a malicious image to the codec—such as via network, local storage, or upstream services—allowing them to read unintended memory contents.
OpenCVE Enrichment