Arbitrary Code Execution Vulnerability in OpenHarmony by OpenHarmony
CVE-2025-24298
7.8HIGH
What is CVE-2025-24298?
OpenHarmony v5.0.3 and earlier versions contain a vulnerability that allows a local attacker to execute arbitrary code within the trust computing base (TCB) due to a use-after-free issue. This flaw can potentially allow unauthorized access and manipulation of the system's operations, making it critical for users to ensure they are operating on patched versions to mitigate risks associated with this weakness.
Affected Version(s)
OpenHarmony v5.0.3