Impact
A flaw has been found in the preview service module of Huawei HarmonyOS that allows an attacker to cause a denial of service. The vulnerability is a weakness in access control (CWE‑264) and can lead to a loss of availability if an attacker can trigger the service to consume excessive resources or crash. No information is provided about data disclosure or integrity impact. The attack would compromise the normal operation of the device by making the preview feature unusable or unstable.
Affected Systems
The affected product is Huawei HarmonyOS. Specific affected versions are not listed in the advisory, so all releases that include the preview service module may need to be evaluated. The advisory does not specify which versions or builds are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity, while the EPSS score is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The preview service module is likely exposed at the application level, which suggests that the possible attack vector could be remote over the network or local if the device is compromised. Based on the description, the attacker would need to send a specially crafted request to the preview service to trigger a resource exhaustion or crash, leading to denial of service.
OpenCVE Enrichment