Local Code Execution Vulnerability in OpenHarmony by OpenHarmony
CVE-2025-27128
7.8HIGH
What is CVE-2025-27128?
A vulnerability exists in OpenHarmony versions prior to v5.0.3 that permits a local attacker to execute arbitrary code within the trusted computing base (TCB). This arises due to a use-after-free error, which can be exploited to manipulate memory and execute unauthorized commands. Attackers leveraging this vulnerability can compromise the integrity and security of the system, risking data confidentiality and system stability.
Affected Version(s)
OpenHarmony v5.0.3