Executive brief
A vulnerability in the OpenHarmony operating system allows a local user to gain unauthorized access to sensitive information. OpenHarmony is an open-source operating system designed for smart devices and IoT hardware. An attacker with existing low-level access to a device could exploit this flaw to bypass privacy protections and leak data, potentially compromising user confidentiality.
Technical details
A signal handler race condition (CWE-364) exists in OpenHarmony v6.0 and earlier. The vulnerability allows a local attacker with low privileges to exploit timing discrepancies during signal handling to access memory or data that should otherwise be protected. This results in a high impact on confidentiality but does not directly affect system integrity or availability. The attack requires local access to the device and does not require user interaction.
Affected products
- OpenHarmony OpenHarmony v6.0 and prior versions
Timeline
- 2026-05-19: disclosed: Initial publication of the CVE record.