Junglewise Threat Intelligence

CVE-2026-58551: Huawei HarmonyOS out-of-bounds read in image codec module

CVE-2026-58551 · Severity: medium · CVSS 5.1 · Published 2026-07-15

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A vulnerability exists in the image processing component of Huawei HarmonyOS, which is used across smartphones, tablets, laptops, and smartwatches. An exploit could allow an attacker to read sensitive information from the device's memory that should otherwise be protected. This could lead to the unauthorized disclosure of private user data or system information.

Technical details

An out-of-bounds read vulnerability exists in the image codec module of Huawei HarmonyOS version 6.1.0. The flaw is categorized as a buffer copy without checking the size of input (CWE-120). An attacker can exploit this via a local attack vector without requiring special privileges or user interaction. Successful exploitation allows the attacker to read data outside the intended buffer, potentially compromising service confidentiality and system availability. Huawei has addressed this in their July 2026 security updates.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-07-08: patched: Huawei released security bulletins addressing the vulnerability.
  • 2026-07-15: disclosed: CVE record published and NVD entry created.

References

Related threats