Impact
The vulnerability is a null pointer dereference in the HarmonyOS image codec module, which can cause the system to crash and become unavailable. The impact is limited to availability loss; there is no evidence of data compromise or integrity violation. Exploitation would require the attacker to supply a crafted image that triggers the fault.
Affected Systems
Huawei HarmonyOS is affected, with all device categories—smartphones, laptops, vision, and wearables—covered in the August 2026 support bulletins. The specific affected versions are not listed, indicating that all current releases prior to a forthcoming patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4 indicates moderate severity, while the EPSS score is not available and the vulnerability is not in the CISA KEV catalog. The likely attack vector involves delivering malicious image data to the image codec, a vector that is plausible for any user who opens a corrupted image file or receives a malicious attachment. Consequently, the risk is moderate and focused on availability.
OpenCVE Enrichment