Executive brief
A vulnerability exists in the media platform of Huawei devices running HarmonyOS. This component is responsible for processing multimedia content like audio and video. If exploited, the vulnerability could cause the media service to crash or become unresponsive, potentially disrupting the use of the device.
Technical details
A stack-based buffer overflow (CWE-121) exists in the media platform component of Huawei HarmonyOS. The vulnerability is triggered when the system processes specifically crafted media content. An attacker with local access and low privileges could exploit this flaw, though it requires some level of user interaction (UI:R). Successful exploitation results in a denial-of-service condition affecting the availability of the media service. The issue is addressed in the May 2026 security updates for affected Huawei phones, tablets, PCs, and wearables.
Affected products
- Huawei HarmonyOS 6.0.0, 6.1.0
Timeline
- 2026-05-07: patched: Huawei released security bulletins for May 2026.
- 2026-05-15: disclosed: NVD published the CVE record.