Junglewise Threat Intelligence

CVE-2026-27781: OpenHarmony integer overflow denial of service

CVE-2026-27781 · Severity: low · CVSS 3.3 · Published 2026-05-19

Technologies: OpenHarmony. Vendors: OpenHarmony.

Executive brief

A vulnerability in the OpenHarmony operating system allows a local user to cause a denial-of-service (DoS) condition. OpenHarmony is an open-source distributed operating system designed for smart devices. An exploit could allow a malicious user already on the device to crash system components, potentially disrupting device availability and user operations.

Technical details

An integer overflow or wraparound (CWE-190) exists in OpenHarmony v6.0 and earlier versions. A local attacker with low privileges can exploit this flaw to trigger a denial-of-service (DoS) condition. The vulnerability is reachable locally without user interaction. While the specific component within the OS is not named in the advisory, the root cause is identified as an integer overflow, which typically leads to memory corruption or logic errors that crash the affected process. Patch information is available via the OpenHarmony security disclosure for April 2026.

Affected products

  • OpenHarmony OpenHarmony v6.0 and prior versions

Timeline

  • 2026-05-19: advisory: NVD publication date

References

Related threats