Junglewise Threat Intelligence

CVE-2026-25850: OpenHarmony improper preservation of permissions information leak

CVE-2026-25850 · Severity: medium · CVSS 5.5 · Published 2026-05-19

Technologies: OpenHarmony. Vendors: OpenHarmony.

Executive brief

A security vulnerability in the OpenHarmony operating system allows a local user to access sensitive information that should be protected. This issue stems from improper permission management within the system. An attacker with existing access to a device could exploit this to view private data, potentially compromising user privacy or system integrity.

Technical details

An information disclosure vulnerability exists in OpenHarmony v6.0 and earlier versions. The flaw is categorized as CWE-281 (Improper Preservation of Permissions), where the system fails to correctly maintain or enforce access control settings. A local attacker with low privileges can exploit this weakness to bypass intended data restrictions and read sensitive information. The attack requires local access to the device but no user interaction. A fix is expected to be addressed in the OpenHarmony security disclosure updates for May 2026.

Affected products

  • OpenHarmony OpenHarmony v6.0 and prior versions

Timeline

  • 2026-05-19: disclosed: Initial disclosure by OpenHarmony and NVD publication.

References

Related threats