CVE-2025-24298

8.4

OpenHarmony · OpenHarmony

A use after free vulnerability in OpenHarmony v5.0.3 and prior versions allows a local attacker to achieve arbitrary code execution in the Trusted Computing Base (TCB).

Executive summary

A high-severity use after free vulnerability in OpenHarmony v5.0.3 and prior versions permits local attackers to execute arbitrary code with elevated system privileges.

Vulnerability

This is a use after free flaw (CWE-416) within the Trusted Computing Base. It requires a local attacker to have low-level user privileges to trigger the memory corruption and execute arbitrary code.

Business impact

The ability for a local attacker to execute arbitrary code within the Trusted Computing Base poses a severe threat to the integrity and confidentiality of the entire system. Given the CVSS score of 8.4, this vulnerability represents a significant risk, as it effectively bypasses standard security boundaries and could lead to full system compromise or unauthorized access to sensitive hardware-backed data.

Remediation

Immediate Action: Consult the official OpenHarmony security disclosure portal to identify and apply the specific security patch or firmware update provided by the vendor.

Proactive Monitoring: Monitor system logs for unusual process crashes or unauthorized attempts to interact with the Trusted Computing Base interfaces.

Compensating Controls: Limit physical and local access to the affected devices to trusted personnel only, as the attack vector requires local presence.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability, combined with its impact on the core security architecture of OpenHarmony, necessitates an urgent review of current device patch levels. Administrators should prioritize verifying their software versions against the vendor advisory and deploying available updates immediately to mitigate the risk of local code execution.

More OpenHarmony CVEs

Sources