Arbitrary Code Execution in OpenHarmony Pre-Installed Apps
CVE-2025-27132
7.8HIGH
What is CVE-2025-27132?
In OpenHarmony versions prior to 5.0.3, a vulnerability exists that permits local attackers to leverage an out-of-bounds write flaw, enabling them to execute arbitrary code within pre-installed applications. This exploitation requires specific conditions, making it potentially impactful in restricted scenarios.
Affected Version(s)
OpenHarmony v4.1.0