Impact
A flaw in Huawei EMUI and Harmony OS vibration service allows uncontrolled resource consumption leading to a denial of service. The vulnerability, classified as CWE‑789, can cause the system to become unresponsive or crash when the vibration service is triggered, thereby impacting device availability.
Affected Systems
The issue affects devices running Huawei EMUI and Huawei Harmony OS. No specific version numbers are indicated in the advisory, so all current releases are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score below 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation. The probable attack vector is through the vibration service, which could be invoked by a local malicious application or through other interactions with the device, potentially allowing an attacker to trigger repeated resource exhaustion and cause the device to hang or restart.
OpenCVE Enrichment