Junglewise Threat Intelligence

CVE-2026-25110: OpenHarmony NULL pointer dereference causing denial of service

CVE-2026-25110 · Severity: low · CVSS 3.3 · Published 2026-05-19

Technologies: OpenHarmony. Vendors: OpenHarmony.

Executive brief

A vulnerability in the OpenHarmony operating system allows a local user to cause a denial-of-service (DoS) condition. This means an individual with existing access to a device could potentially crash the system or specific services, disrupting operations. While it does not allow for data theft, it can impact the reliability and availability of devices running this software.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists in OpenHarmony v6.0 and earlier versions. A local attacker with low privileges can exploit this flaw to trigger a denial-of-service (DoS) state. The attack does not require user interaction and has no impact on data confidentiality or integrity. The vulnerability was disclosed by the OpenHarmony project in their April 2026 security disclosure.

Affected products

  • OpenHarmony OpenHarmony v6.0 and prior versions

Timeline

  • 2026-05-19: disclosed: NVD publication date

References

Related threats