Arbitrary Code Execution Vulnerability in OpenHarmony by OpenHarmony
CVE-2025-24298

7.8HIGH

Key Information:

Vendor
CVE Published:
11 August 2025

What is CVE-2025-24298?

OpenHarmony v5.0.3 and earlier versions contain a vulnerability that allows a local attacker to execute arbitrary code within the trust computing base (TCB) due to a use-after-free issue. This flaw can potentially allow unauthorized access and manipulation of the system's operations, making it critical for users to ensure they are operating on patched versions to mitigate risks associated with this weakness.

Affected Version(s)

OpenHarmony v5.0.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.