Junglewise Threat Intelligence

CVE-2026-58550: Huawei HarmonyOS out-of-bounds read in image codec module

CVE-2026-58550 · Severity: medium · CVSS 4 · Published 2026-07-15

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

Huawei HarmonyOS, the operating system used across Huawei smartphones, tablets, laptops, and smartwatches, contains a security vulnerability in its image processing component. An attacker could exploit this flaw to access information that should normally be protected, potentially compromising the privacy of user data or system services. This issue is addressed in the July 2026 security updates for affected devices.

Technical details

An out-of-bounds read vulnerability exists in the image codec module of Huawei HarmonyOS version 6.1.0. The flaw is categorized as a buffer copy without checking the size of input (CWE-120). According to the CVSS vector, the attack vector is local with low complexity and requires no special privileges or user interaction. Successful exploitation allows an attacker to read data beyond the intended buffer, which Huawei notes may affect service confidentiality. Patches were released as part of the July 2026 Huawei security bulletin cycle.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-07-08: patched: Huawei security bulletin updated with patch information.
  • 2026-07-15: advisory: NVD published the CVE record.

References

Related threats