CVE-2025-27128

8.4

OpenHarmony · OpenHarmony

A use after free vulnerability in OpenHarmony versions 5.0.3 and prior allows a local attacker to achieve arbitrary code execution within the TCB.

Executive summary

A high-severity use after free vulnerability in OpenHarmony versions 5.0.3 and prior permits local attackers to execute arbitrary code within the Trusted Computing Base.

Vulnerability

The vulnerability is a use after free flaw (CWE-416) within the Trusted Computing Base (TCB). It requires a local attacker with low privileges to trigger the memory corruption, leading to a potential compromise of the system core.

Business impact

The ability for a local attacker to execute arbitrary code within the TCB represents a critical security failure, as it bypasses standard system protections. Given the CVSS score of 8.4, this vulnerability poses a significant risk of total system compromise, unauthorized data access, and potential persistence for malicious actors who have already gained initial local access.

Remediation

Immediate Action: Update all affected OpenHarmony deployments to the latest version provided by the vendor, ensuring all applicable security patches are applied.

Proactive Monitoring: Monitor system logs for unusual process crashes or unexpected behavior within the TCB, which may indicate attempted exploitation of memory corruption vulnerabilities.

Compensating Controls: Implement strict local access controls and ensure that only authorized users have the ability to execute code or interact with sensitive system components on the device.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a serious risk to system integrity due to its impact on the Trusted Computing Base. Administrators should prioritize identifying all instances of OpenHarmony v5.0.3 within their environment and apply the necessary vendor-supplied updates immediately to remediate the use after free condition.

More OpenHarmony CVEs

Sources