Description
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-07-15
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read has been identified within the image codec module of Huawei HarmonyOS. The flaw, classified as CWE-120, permits an attacker to read memory beyond the intended buffer boundaries, potentially exposing sensitive data. Successful exploitation would compromise the confidentiality of data handled by the system, but does not offer direct privilege escalation or denial of service.

Affected Systems

All devices running Huawei HarmonyOS are impacted, encompassing consumer smartphones, laptops, vision devices, and wearables. The advisory does not list specific firmware revisions, so any installation based on HarmonyOS remains at risk until patched.

Risk and Exploitability

The CVSS score is 4.0, indicating a moderate risk, while the EPSS score is below 1 %, suggesting that exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve the delivery of a malicious image to the system—such as via camera, photo gallery, or messaging applications—allowing local or remote attackers with image handling privileges to trigger the out-of-bounds read.

Generated by OpenCVE AI on August 1, 2026 at 08:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest HarmonyOS firmware update that patches the out-of-bounds read in the image codec as soon as it is released.
  • Disable or limit functions that accept external image input, such as camera capture, photo gallery, or messaging attachments, until the patch is applied.
  • Enable automatic system updates and monitor Huawei’s security bulletins for the release of the fix, and refrain from opening untrusted images during the interim.

Generated by OpenCVE AI on August 1, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Huawei HarmonyOS Image Codec May Leak Sensitive Data

Tue, 28 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read in HarmonyOS Image Codec Module

Sat, 25 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read in HarmonyOS Image Codec Module

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in HarmonyOS Image Codec Leading to Potential Confidentiality Breach

Fri, 17 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in HarmonyOS Image Codec Leading to Potential Confidentiality Breach

Wed, 15 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-07-15T13:09:03.769Z

Reserved: 2026-07-01T10:03:11.403Z

Link: CVE-2026-58553

cve-icon Vulnrichment

Updated: 2026-07-15T13:08:54.797Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')