Junglewise Threat Intelligence

CVE-2026-58549: Huawei HarmonyOS out-of-bounds read in image codec module

CVE-2026-58549 · Severity: medium · CVSS 4 · Published 2026-07-15

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the image processing component of Huawei HarmonyOS devices, including smartphones, tablets, PCs, and smartwatches. If exploited, this flaw could allow unauthorized access to sensitive information stored in the device's memory. This may compromise the confidentiality of user data or system services.

Technical details

An out-of-bounds read vulnerability exists in the image codec module of Huawei HarmonyOS 6.1.0. The flaw is categorized as a buffer copy without checking the size of input (CWE-120). An attacker could exploit this via a local attack vector to read data beyond the intended buffer, potentially leading to the disclosure of sensitive information from the service's memory space. The vulnerability has been addressed in the July 2026 security update for affected Huawei devices.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-07-08: patched: Huawei released security bulletins addressing the issue.
  • 2026-07-15: advisory: NVD published the CVE record.

References

Related threats