Local Code Execution Vulnerability in OpenHarmony by OpenHarmony
CVE-2025-23409
7.8HIGH
What is CVE-2025-23409?
In OpenHarmony versions up to v5.0.2, a vulnerability exists that allows local attackers to execute arbitrary code in pre-installed applications through a use after free condition. This flaw, while exploitable only in limited scenarios, poses a significant risk to user data and system integrity. Immediate attention to patching and mitigation strategies is recommended to protect affected systems.
Affected Version(s)
OpenHarmony v4.1.0