Description
Out-of-bounds read vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-09-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Availability
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an out-of-bounds read in the graphics module of HarmonyOS. This flaw allows an attacker to read beyond the bounds of a buffer, potentially leading to memory disclosure or application crashes. The impact is limited to availability, as the exploit can cause crashes or interruptions but does not provide direct code execution or confidentiality compromise. The weakness is identified as CWE-125.

Affected Systems

The affected systems are devices running Huawei HarmonyOS. No specific version information is provided, so all HarmonyOS releases potentially impacted until a patch is released. The references point to various product categories such as consumer devices, laptops, vision devices, and wearables.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity, with an unknown EPSS score and no listing in the CISA KEV catalog. The attack vector is not detailed in the description, but the vulnerability is in the graphics module, so it may be triggered by crafted graphic data or a malicious user via applications that render graphics. No official exploitation technique or conditions are documented, so risk remains moderate. Availability is the primary risk, and the lack of exploitability data suggests limited but possible exploitation.

Generated by OpenCVE AI on September 9, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the HarmonyOS security patch released by Huawei to fix the graphics module issue.
  • Disable any graphics features that process user-supplied or network‑received content if the OS allows configuration.
  • Keep devices updated with the latest HarmonyOS release to benefit from future security fixes and monitor for any crashes attributable to graphics rendering.

Generated by OpenCVE AI on September 9, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Vulnerability in HarmonyOS Graphics Module

Wed, 09 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-09T20:51:33.622Z

Reserved: 2026-08-27T09:26:59.599Z

Link: CVE-2026-81646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:20:19.430

Modified: 2026-09-09T21:17:05.023

Link: CVE-2026-81646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses