Executive brief
A security vulnerability has been identified in OpenHarmony, an open-source operating system designed for smart devices. A local attacker with basic access to a device could exploit this flaw to execute unauthorized commands or cause the system to crash. This could lead to a loss of device control or a disruption of services for users and organizations relying on OpenHarmony-powered hardware.
Technical details
A use-after-free vulnerability (CWE-416) exists in OpenHarmony v6.0 and earlier versions. The flaw occurs when the system continues to use a pointer after it has been freed, which can be manipulated by a local attacker to execute arbitrary code or cause a denial-of-service (system crash). The attack requires local access with low privileges and no user interaction. While the CVSS vector provided by the CNA (AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H) emphasizes high availability impact, the vulnerability description confirms the potential for arbitrary code execution. Users should refer to the OpenHarmony security disclosure for May 2026 for patching information.
Affected products
- OpenHarmony OpenHarmony v6.0 and prior versions
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory