Huawei HarmonyOS 3D Engine Module glTF Model Loading Input Validation Vulnerability

Vulnerability

A vulnerability exists in the 3D engine module of Huawei HarmonyOS devices, specifically in versions through 5.0.0. This vulnerability arises because input parameters are not properly validated during the loading of glTF models. As a result, successful exploitation of this issue could disrupt the availability of the service.

Impact

Exploitation of this vulnerability may lead to a denial-of-service condition, causing the application or service to become unavailable or unresponsive.

Remediation

Users can refer to the January 2025 Huawei Security Bulletin for guidance on applying the available patch.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
3.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.