Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

All 177 CVE vulnerabilities found in OpenHarmony, with AI-generated Chinese analysis, references, and POCs.

This page aggregates OpenHarmony vulnerability disclosures, focusing on software weaknesses in the operating system ecosystem maintained by the open-source community. It collects data on memory corruption, race conditions, and logic flaws found within kernel and middleware components, covering advisories published over the past three years of active development. Readers can use this resource to track how the project addresses critical security flaws, understand common weakness classes in embedded and IoT environments, and review the vulnerability history for specific OpenHarmony modules. The data highlights the iterative nature of the codebase, showing how patches are issued and integrated into release branches. By examining these entries, developers and security teams can identify recurring patterns in defect types, assess the risk exposure of systems running OpenHarmony, and verify that remediations have been properly applied in their deployment stacks. This aggregation serves as a neutral reference for auditing compliance and evaluating the security maturity of the platform without relying on single-vendor communication channels.

Vendor: OpenHarmony

CVE ID Title CVSS Severity Published
CVE-2025-26693 security_access_token has an improper preservation of permissions vulnerability CWE-281 3.3 Low 2025-06-08
CVE-2025-26691 telephony_call_manager has an improper preservation of permissions vulnerability CWE-281 5.5 Medium 2025-06-08
CVE-2025-27131 kernel_liteos_m has an improper input vulnerability CWE-20 6.1 Medium 2025-06-08
CVE-2025-24493 kernel_liteos_a has a race condition vulnerability CWE-362 5.5 Medium 2025-06-08
CVE-2025-25217 arkui_ace_enginehas a NULL pointer dereference vulnerability CWE-476 3.3 Low 2025-06-08
CVE-2025-23235 arkcompiler_ets_runtime has an out-of-bounds write vulnerability CWE-125 3.3 Low 2025-06-08
CVE-2025-21082 arkui_ace_engine has a type confusion vulnerability CWE-843 3.3 Low 2025-06-08
CVE-2025-20063 arkui_ace_engine has a type confusion vulnerability CWE-843 3.3 Low 2025-06-08
CVE-2025-25052 arkcompiler_ets_runtime has a buffer overflow vulnerability CWE-120 3.3 Low 2025-05-06
CVE-2025-27241 multimedia_av_codec has a NULL pointer dereference vulnerability CWE-476 3.3 Low 2025-05-06
CVE-2025-27248 ai_neural_network_runtime has a NULL pointer dereference vulnerability CWE-476 3.3 Low 2025-05-06
CVE-2025-22886 distributeddatamgr_udmf has a memory leak vulnerability CWE-401 3.3 Low 2025-05-06
CVE-2025-27132 arkcompiler_ets_runtime has an out-of-bounds write vulnerability CWE-787 3.8 Low 2025-05-06
CVE-2025-25218 third_party_mksh has a NULL pointer dereference vulnerability CWE-476 3.3 Low 2025-05-06
CVE-2025-27534 arkcompiler_ets_runtime has an out-of-bounds read vulnerability CWE-125 3.3 Low 2025-04-07
CVE-2025-25057 third_party_NuttX has a memory leak vulnerability CWE-401 3.3 Low 2025-04-07
CVE-2025-24304 arkcompiler_ets_runtime has an out-of-bounds write vulnerability CWE-787 3.3 Low 2025-04-07
CVE-2025-22851 Liteos_A has an integer overflow vulnerability CWE-190 6.5 Medium 2025-04-07
CVE-2025-22842 arkcompiler_ets_runtime has an out-of-bounds read vulnerability CWE-125 3.3 Low 2025-04-07
CVE-2025-22452 arkcompiler_ets_runtime has an out-of-bounds read vulnerability CWE-125 3.3 Low 2025-04-07
CVE-2025-20102 arkcompiler_ets_runtime has an out-of-bounds read vulnerability CWE-125 3.3 Low 2025-04-07
CVE-2025-24309 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 3.8 Low 2025-03-04
CVE-2025-24301 Arkcompiler Ets Runtime has an UAF vulnerability CWE-416 3.8 Low 2025-03-04
CVE-2025-23420 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 3.8 Low 2025-03-04
CVE-2025-23418 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability CWE-125 3.3 Low 2025-03-04
CVE-2025-23414 Arkcompiler Ets Runtime has an UAF vulnerability CWE-416 3.8 Low 2025-03-04
CVE-2025-23409 Communication Dsoftbus has an UAF vulnerability CWE-416 3.8 Low 2025-03-04
CVE-2025-23240 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 3.8 Low 2025-03-04
CVE-2025-23234 Arkcompiler Ets Runtime has a buffer overflow vulnerability CWE-120 3.3 Low 2025-03-04
CVE-2025-22897 Arkcompiler Ets Runtime has a buffer overflow vulnerability CWE-120 3.3 Low 2025-03-04

All 177 known CVE vulnerabilities affecting OpenHarmony with full Chinese analysis, references, and POCs where available.