CVE-2026-27648

8.8

OpenHarmony · OpenHarmony

OpenHarmony v5.0.3 through v6.0 contains an out-of-bounds write vulnerability that could allow a low-privileged local or network-based attacker to cause system instability or execute code.

Executive summary

An out-of-bounds write vulnerability in OpenHarmony versions 5.0.3 through 6.0 poses a severe risk of system corruption or unauthorized code execution.

Vulnerability

The software contains an out-of-bounds write vulnerability (CWE-787), which can be triggered by an attacker with low privileges. This flaw allows for memory corruption that may result in arbitrary code execution or denial of service.

Business impact

With a CVSS score of 8.8, this vulnerability is highly dangerous as it permits an attacker to potentially gain elevated control over the underlying device or system. In enterprise environments, this could lead to the compromise of sensitive data or the total unavailability of critical OpenHarmony-based services.

Remediation

Immediate Action: Review the official OpenHarmony security disclosures and apply the latest vendor-supplied patches or firmware updates as soon as they become available.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts that may indicate attempted exploitation of memory corruption vulnerabilities.

Compensating Controls: Limit the exposure of OpenHarmony services to untrusted networks and enforce strict least-privilege policies for all system users to minimize the potential attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing OpenHarmony 5.0.3 through 6.0 should urgently monitor the vendor's security portal for a patch. Given the high CVSS score, any device running these versions should be treated as high-risk until the vulnerability is addressed.