Impact
An out-of-bounds read has been identified within the image codec module of Huawei HarmonyOS. The flaw, classified as CWE-120, permits an attacker to read memory beyond the intended buffer boundaries, potentially exposing sensitive data. Successful exploitation would compromise the confidentiality of data handled by the system, but does not offer direct privilege escalation or denial of service.
Affected Systems
All devices running Huawei HarmonyOS are impacted, encompassing consumer smartphones, laptops, vision devices, and wearables. The advisory does not list specific firmware revisions, so any installation based on HarmonyOS remains at risk until patched.
Risk and Exploitability
The CVSS score is 4.0, indicating a moderate risk, while the EPSS score is below 1 %, suggesting that exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve the delivery of a malicious image to the system—such as via camera, photo gallery, or messaging applications—allowing local or remote attackers with image handling privileges to trigger the out-of-bounds read.
OpenCVE Enrichment