Local Code Execution Vulnerability in OpenHarmony by OpenHarmony
CVE-2025-27128
7.8HIGH
What is CVE-2025-27128?
A vulnerability exists in OpenHarmony versions prior to v5.0.3 that permits a local attacker to execute arbitrary code within the trusted computing base (TCB). This arises due to a use-after-free error, which can be exploited to manipulate memory and execute unauthorized commands. Attackers leveraging this vulnerability can compromise the integrity and security of the system, risking data confidentiality and system stability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenHarmony v5.0.3
