Executive brief
A vulnerability in the OpenHarmony operating system allows remote attackers to execute unauthorized code within pre-installed applications. OpenHarmony is an open-source operating system designed for smart devices and IoT hardware. If exploited, this could allow an attacker to take control of device functions, access sensitive user data, or disrupt the operation of the device.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in OpenHarmony v6.0 and earlier. The flaw allows a remote attacker with low privileges to achieve arbitrary code execution within the context of pre-installed applications. The attack vector is network-based and does not require user interaction, though it does require a low level of authentication. Successful exploitation results in a high impact on confidentiality, integrity, and availability. Users are advised to refer to the OpenHarmony security disclosure for April 2026 for patching information.
Affected products
- OpenHarmony OpenHarmony v6.0 and prior versions
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory