Description
Out-of-bounds read vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

The flaw is an out-of-bounds read in the graphics module of Huawei HarmonyOS. It can cause application crashes or system instability, leading to a loss of availability. The weakness corresponds to CWE‑680.

Affected Systems

The vulnerability exists in Huawei’s HarmonyOS and may affect any device that runs the impacted graphics driver, including consumer, laptop, and vision models referenced by Huawei’s official bulletin. No specific firmware or build versions are listed, so all HarmonyOS deployments should verify that the graphics module has been updated to a secure version.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of current exploitation. The most likely attack vector involves delivering malformed graphics data to the affected module; exploitation would disrupt availability but does not directly compromise confidentiality or integrity.

Generated by OpenCVE AI on September 9, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HarmonyOS security patch released by Huawei, as announced in the official support bulletins.
  • Verify that all devices running HarmonyOS are updated to a build that incorporates the graphics module fix.
  • If an immediate patch cannot be applied, establish device‑level controls to disable or limit the use of the affected graphics features until the patch is deployed.

Generated by OpenCVE AI on September 9, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Graphics Module Out‑of‑Bounds Read Vulnerability in Huawei HarmonyOS

Wed, 09 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-680
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-09T20:51:33.484Z

Reserved: 2026-08-27T09:26:59.599Z

Link: CVE-2026-81647

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:20:19.623

Modified: 2026-09-09T21:17:05.117

Link: CVE-2026-81647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow