Junglewise Threat Intelligence

CVE-2026-24792: OpenHarmony remote code execution in pre-installed apps

CVE-2026-24792 · Severity: high · CVSS 8.1 · Published 2026-05-19

Technologies: OpenHarmony. Vendors: OpenHarmony.

Executive brief

OpenHarmony is an open-source operating system used across various smart devices and IoT hardware. A security vulnerability in version 6.0 and earlier allows a remote attacker to execute unauthorized code within pre-installed applications. This could lead to the compromise of sensitive user data or a complete loss of control over the affected device.

Technical details

A race condition vulnerability (CWE-364) exists in the signal handling mechanisms of OpenHarmony v6.0 and earlier. This flaw allows a remote attacker with low privileges to execute arbitrary code within the context of pre-installed applications. The vulnerability is reachable over the network without user interaction. Successful exploitation could result in high impacts to confidentiality and availability, potentially allowing an attacker to gain persistent access or disrupt system services. Users are advised to monitor for security updates from the OpenHarmony project.

Affected products

  • OpenHarmony OpenHarmony v6.0 and prior versions

Timeline

  • 2026-05-19: disclosed: CVE published to NVD dataset

References

Related threats