Junglewise Threat Intelligence

CVE-2026-58552: Huawei HarmonyOS out-of-bounds read in image codec module

CVE-2026-58552 · Severity: medium · CVSS 5.1 · Published 2026-07-15

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A vulnerability exists in the image processing component of Huawei HarmonyOS, the operating system used across Huawei smartphones, tablets, and smart devices. An attacker could exploit this flaw to read sensitive information from the device's memory that should otherwise be protected. This could lead to the unauthorized disclosure of private user data or system information.

Technical details

An out-of-bounds read vulnerability exists in the image codec module of Huawei HarmonyOS 6.1.0. The flaw is categorized as a buffer copy without checking the size of input (CWE-120). An attacker with local access can exploit this vulnerability to read data beyond the intended buffer, potentially leading to the disclosure of sensitive system or service information. The vulnerability has been addressed in the July 2026 security updates for Huawei phones, tablets, PCs, and wearables.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-07-08: patched: Huawei published security bulletins addressing the issue.
  • 2026-07-15: disclosed: CVE record published and NVD entry created.

References

Related threats