Junglewise Threat Intelligence

CVE-2026-58553: Huawei HarmonyOS out-of-bounds read in image codec module

CVE-2026-58553 · Severity: medium · CVSS 4 · Published 2026-07-15

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

Huawei HarmonyOS contains a security vulnerability in its image processing component used across phones, tablets, and wearable devices. An attacker could exploit this flaw to read data outside of intended memory boundaries, potentially leading to the exposure of sensitive information. This issue affects the confidentiality of services running on the device.

Technical details

An out-of-bounds read vulnerability exists in the image codec module of Huawei HarmonyOS version 6.1.0. The flaw is categorized as a buffer copy without checking the size of input (CWE-120). An attacker can exploit this via a local attack vector to read memory outside of the intended buffer. Successful exploitation could lead to the disclosure of sensitive information, impacting the confidentiality of the affected service. Huawei has addressed this in their July 2026 security updates.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-07-08: patched: Huawei released security bulletins addressing the issue.
  • 2026-07-15: advisory: NVD published the CVE record.

References

Related threats