Junglewise Threat Intelligence

CVE-2026-81646: Huawei HarmonyOS out-of-bounds read in graphics module

CVE-2026-81646 · Severity: medium · CVSS 5.9 · Published 2026-09-09

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

HarmonyOS is Huawei's operating system for smartphones, tablets, and PCs. An out-of-bounds read vulnerability in the graphics rendering module could allow an attacker to crash the system or leak sensitive memory contents, potentially affecting system availability and data confidentiality.

Technical details

An out-of-bounds read vulnerability exists in the graphics module of HarmonyOS, allowing memory beyond allocated buffers to be read. The vulnerability is triggered during graphics processing operations and requires no special authentication or user interaction. Successful exploitation can lead to denial of service (system crash) or information disclosure through memory leakage. This affects HarmonyOS 6.1.0, and patches are available through Huawei's monthly security updates.

Affected products

  • Huawei HarmonyOS 6.1.0

Timeline

  • 2026-09-09: disclosed: Published in Huawei security bulletin for September 2026
  • 2026-09-05: advisory: Security bulletin updated on this date

References

Related threats