Impact
An out-of-bounds read has been identified in HarmonyOS’s image codec module. The flaw permits an attacker to read data beyond the intended buffer borders, allowing acquisition of sensitive information from memory without write privileges. This leads to a confidentiality compromise and is classified under CWE-120, representing unsafe handling of buffer sizes.
Affected Systems
The vulnerability affects Huawei HarmonyOS. No specific release version is listed, so all HarmonyOS product lines that include the current image codec library are potentially at risk unless a patch has been applied.
Risk and Exploitability
The CVSS score of 5.1 marks moderate severity, while the EPSS score of less than 1 % suggests a low but non-zero chance of exploitation. HarmonyOS is not listed in the CISA KEV catalog, reducing the promptness of a coordinated response. The attack vector is inferred to be local or remote via a crafted image file delivered to the device; official mitigation steps are not yet released.
OpenCVE Enrichment