Description
DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-07-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Huawei EMUI and Harmony OS vibration service allows uncontrolled resource consumption leading to a denial of service. The vulnerability, classified as CWE‑789, can cause the system to become unresponsive or crash when the vibration service is triggered, thereby impacting device availability.

Affected Systems

The issue affects devices running Huawei EMUI and Huawei Harmony OS. No specific version numbers are indicated in the advisory, so all current releases are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while an EPSS score below 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation. The probable attack vector is through the vibration service, which could be invoked by a local malicious application or through other interactions with the device, potentially allowing an attacker to trigger repeated resource exhaustion and cause the device to hang or restart.

Generated by OpenCVE AI on July 31, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware or OS to the latest Huawei release that addresses the vibration service flaw.
  • If no firmware update is available, disable the vibration service in system settings or install a custom firmware that removes the component.
  • Monitor device logs for vibration‑related crashes or hangs and report any incidents to Huawei support for further assistance.

Generated by OpenCVE AI on July 31, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in Huawei EMUI and Harmony OS Vibration Service

Wed, 29 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Huawei Vibrator Service

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei emui
Huawei harmonyos
Vendors & Products Huawei
Huawei emui
Huawei harmonyos

Sat, 25 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Huawei Vibrator Service

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Denial of Service in Huawei EMUI and Harmony OS Vibration Service

Fri, 17 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Denial of Service in Huawei EMUI and Harmony OS Vibration Service

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-07-15T13:03:19.123Z

Reserved: 2026-07-01T10:03:11.403Z

Link: CVE-2026-58559

cve-icon Vulnrichment

Updated: 2026-07-15T13:03:15.427Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value