Executive brief
A vulnerability in the OpenHarmony operating system allows a local user to trigger a permanent denial-of-service state. This flaw can render the affected device unusable, requiring manual intervention or hardware replacement as the system cannot recover on its own. This poses a significant risk to device availability and operational continuity for organizations using OpenHarmony-based hardware.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in OpenHarmony v6.0 and earlier. A local attacker with low privileges can exploit this flaw to trigger a denial-of-service (DoS) condition. According to the advisory, the resulting system failure is non-recoverable, suggesting corruption of critical system components or firmware. While the provided CVSS vector (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N) strangely emphasizes Confidentiality and Integrity over Availability, the descriptive text explicitly confirms a permanent DoS impact.
Affected products
- OpenHarmony OpenHarmony v6.0 and prior versions
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory