Impact
The vulnerability is an out-of-bounds read in the graphics module of HarmonyOS. This flaw allows an attacker to read beyond the bounds of a buffer, potentially leading to memory disclosure or application crashes. The impact is limited to availability, as the exploit can cause crashes or interruptions but does not provide direct code execution or confidentiality compromise. The weakness is identified as CWE-125.
Affected Systems
The affected systems are devices running Huawei HarmonyOS. No specific version information is provided, so all HarmonyOS releases potentially impacted until a patch is released. The references point to various product categories such as consumer devices, laptops, vision devices, and wearables.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity, with an unknown EPSS score and no listing in the CISA KEV catalog. The attack vector is not detailed in the description, but the vulnerability is in the graphics module, so it may be triggered by crafted graphic data or a malicious user via applications that render graphics. No official exploitation technique or conditions are documented, so risk remains moderate. Availability is the primary risk, and the lack of exploitability data suggests limited but possible exploitation.
OpenCVE Enrichment