Executive brief
HarmonyOS is Huawei's operating system for smartphones, tablets, and PCs. An out-of-bounds read vulnerability in the graphics rendering module could allow an attacker to crash the system or leak sensitive memory contents, potentially affecting system availability and data confidentiality.
Technical details
An out-of-bounds read vulnerability exists in the graphics module of HarmonyOS, allowing memory beyond allocated buffers to be read. The vulnerability is triggered during graphics processing operations and requires no special authentication or user interaction. Successful exploitation can lead to denial of service (system crash) or information disclosure through memory leakage. This affects HarmonyOS 6.1.0, and patches are available through Huawei's monthly security updates.
Affected products
- Huawei HarmonyOS 6.1.0
Timeline
- 2026-09-09: disclosed: Published in Huawei security bulletin for September 2026
- 2026-09-05: advisory: Security bulletin updated on this date