Impact
A null pointer dereference was found in the image codec module of HarmonyOS. When a corrupted image is decoded, the codec can crash, causing the affected process or device to become unavailable. The primary consequence is service interruption rather than data loss or disclosure.
Affected Systems
The vulnerability affects devices running Huawei HarmonyOS. No specific device families or software versions are listed, so all released HarmonyOS installations potentially carry the flaw.
Risk and Exploitability
The CVSS score is 4, indicating moderate severity. With no EPSS score published and the issue not marked in the KEV catalog, the likelihood of widespread exploitation is currently low. Based on the description, the likely attack vector involves the delivery of a malformed image—either locally or remotely—to the codec module, triggering a crash and denial of service.
OpenCVE Enrichment