Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

Browse all 177 CVE security advisories affecting OpenHarmony. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenHarmony is an open-source operating system designed for distributed scenarios across smart devices, IoT, and industrial applications. Its architecture emphasizes modularity and scalability, allowing developers to tailor the system for diverse hardware constraints. Historically, the project has faced 167 recorded Common Vulnerabilities and Exposures (CVEs), with recurring issues primarily involving buffer overflows, use-after-free errors, and improper input validation. These flaws often lead to remote code execution or privilege escalation, particularly within the device communication and permission management modules. While no single catastrophic incident has defined its history, the high volume of CVEs highlights challenges in maintaining rigorous security standards across its fragmented ecosystem. The project relies on community-driven patches and formal verification efforts to mitigate risks, though the complexity of its distributed nature continues to present significant attack surface challenges for security researchers and administrators alike.

Top products by OpenHarmony: OpenHarmony
CVE ID Title CVSS Severity Published
CVE-2025-22847 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability — OpenHarmony CWE-125 3.3 Low 2025-03-04
CVE-2025-22841 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability — OpenHarmony CWE-125 3.3 Low 2025-03-04
CVE-2025-22837 Arkcompiler Ets Runtime has a NULL pointer dereference vulnerability — OpenHarmony CWE-476 3.3 Low 2025-03-04
CVE-2025-22835 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 3.8 Low 2025-03-04
CVE-2025-22443 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability — OpenHarmony CWE-125 3.3 Low 2025-03-04
CVE-2025-21098 Liteos-A has an insecure storage of sensitive information vulnerability — OpenHarmony CWE-922 5.5 Medium 2025-03-04
CVE-2025-21097 Arkcompiler Ets Runtime has a NULL pointer dereference vulnerability — OpenHarmony CWE-476 3.3 Low 2025-03-04
CVE-2025-21089 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability — OpenHarmony CWE-125 3.3 Low 2025-03-04
CVE-2025-21084 Arkcompiler Ets Runtime has an NULL pointer dereference vulnerability — OpenHarmony CWE-476 3.8 Low 2025-03-04
CVE-2025-20626 Arkcompiler Ets Runtime has an UAF vulnerability — OpenHarmony CWE-416 3.8 Low 2025-03-04
CVE-2025-20091 Communication Dsoftbus has an UAF vulnerability — OpenHarmony CWE-416 3.8 Low 2025-03-04
CVE-2025-20081 Communication Dsoftbus has an UAF vulnerability — OpenHarmony CWE-416 3.8 Low 2025-03-04
CVE-2025-20042 Liteos-A has an out of bounds read vulnerability — OpenHarmony CWE-125 5.5 Medium 2025-03-04
CVE-2025-20024 Arkcompiler Ets Runtime has an integer overflow vulnerability — OpenHarmony CWE-190 3.8 Low 2025-03-04
CVE-2025-20021 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability — OpenHarmony CWE-125 3.3 Low 2025-03-04
CVE-2025-20011 Communication Dsoftbus has a memory leak vulnerability — OpenHarmony CWE-401 3.3 Low 2025-03-04
CVE-2025-0587 Arkcompiler Ets Runtime has an integer overflow vulnerability — OpenHarmony CWE-190 3.8 Low 2025-03-04
CVE-2025-0304 Liteos_a has an use after free vulnerability — OpenHarmony CWE-416 8.8 High 2025-02-07
CVE-2025-0303 Liteos_a has a buffer overflow vulnerability — OpenHarmony CWE-120 8.8 High 2025-02-07
CVE-2025-0302 Liteos_a has an integer overflow read vulnerability — OpenHarmony CWE-190 5.5 Medium 2025-02-07
CVE-2024-54030 Communication_dsoftbus has an UAF vulnerability — OpenHarmony CWE-416 4.4 Medium 2025-01-07
CVE-2024-47398 Liteos_a has an out-of-bounds write vulnerability — OpenHarmony CWE-787 8.8 High 2025-01-07
CVE-2024-45070 Liteos_a has an out-of-bounds read vulnerability — OpenHarmony CWE-125 5.5 Medium 2025-01-07
CVE-2024-9978 Liteos_a has an out-of-bounds read vulnerability — OpenHarmony CWE-125 5.5 Medium 2024-12-03
CVE-2024-12082 Ability Runtime has an out-of-bounds read permission bypass vulnerability — OpenHarmony CWE-125 5.5 Medium 2024-12-03
CVE-2024-10074 Liteos_a has an use after free vulnerability — OpenHarmony CWE-416 8.8 High 2024-12-03
CVE-2024-47402 Liteos_a has an Out-of-bounds Read vulnerability — OpenHarmony CWE-125 3.3 Low 2024-11-05
CVE-2024-47137 Liteos_a has an out-of-bounds Write vulnerability — OpenHarmony CWE-787 8.4 High 2024-11-05
CVE-2024-47404 Liteos_a has a double free vulnerability — OpenHarmony CWE-415 8.4 High 2024-11-05
CVE-2024-47797 Liteos_a has an out-of-bounds Write vulnerability — OpenHarmony CWE-787 8.4 High 2024-11-05

This page lists every published CVE security advisory associated with OpenHarmony. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.