Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
The bug results from improper exception handling in the module responsible for graphics (Graphics module). An unhandled exception can be triggered locally without the need for privileges or user interaction. According to the CVSS vector, the vulnerability has a scope extending beyond the attacked component (Scope: Changed), which may indicate the possibility of affecting isolated system components.
Successful exploitation of the vulnerability may result in a breach of confidentiality of data processed by the device. The high level of integrity and availability indicators in the CVSS vector suggests potentially broader impact on system stability and security.
Apply patches available from the manufacturer according to the references — Huawei security bulletin available at: https://consumer.huawei.com/en/support/bulletin/2024/8/
Devices with Huawei EMUI and Huawei HarmonyOS systems — specific versions indicated in the manufacturer's references (Huawei security bulletin from August 2024).
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHuawei Emui
OSHuawei12.0.013.0.014.0.0Huawei Harmonyos
OSHuawei2.0.02.1.03.0.03.1.04.0.04.2.0
Related vulnerabilities
HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB
Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS
Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS
Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei
Ominięcie weryfikacji nazwy pakietu w module HwIms (Huawei EMUI/HarmonyOS)