Local Code Execution Vulnerability in OpenHarmony by OpenHarmony
CVE-2025-27128

7.8HIGH

Key Information:

Vendor
CVE Published:
11 August 2025

What is CVE-2025-27128?

A vulnerability exists in OpenHarmony versions prior to v5.0.3 that permits a local attacker to execute arbitrary code within the trusted computing base (TCB). This arises due to a use-after-free error, which can be exploited to manipulate memory and execute unauthorized commands. Attackers leveraging this vulnerability can compromise the integrity and security of the system, risking data confidentiality and system stability.

Affected Version(s)

OpenHarmony v5.0.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.