Junglewise Threat Intelligence

CVE-2026-28733: OpenHarmony use-after-free arbitrary code execution

CVE-2026-28733 · Severity: medium · CVSS 6.5 · Published 2026-05-19

Technologies: OpenHarmony. Vendors: OpenHarmony.

Executive brief

A security vulnerability has been identified in OpenHarmony, an open-source operating system designed for smart devices. A local attacker with basic access to a device could exploit this flaw to execute unauthorized commands or cause the system to crash. This could lead to a loss of device control or a disruption of services for users and organizations relying on OpenHarmony-powered hardware.

Technical details

A use-after-free vulnerability (CWE-416) exists in OpenHarmony v6.0 and earlier versions. The flaw occurs when the system continues to use a pointer after it has been freed, which can be manipulated by a local attacker to execute arbitrary code or cause a denial-of-service (system crash). The attack requires local access with low privileges and no user interaction. While the CVSS vector provided by the CNA (AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H) emphasizes high availability impact, the vulnerability description confirms the potential for arbitrary code execution. Users should refer to the OpenHarmony security disclosure for May 2026 for patching information.

Affected products

  • OpenHarmony OpenHarmony v6.0 and prior versions

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory

References

Related threats