Loading
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
Use CWE-416, Openatom vendor hub and Openharmony product page to widen CVE-2025-23409 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-27577, CVE-2025-27128 and CVE-2025-12736 for nearby disclosures in the same product family.