Loading
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
Cite this page
CVE-2025-23420. CVEDatabase.com. Retrieved 3 May 2026. https://cvedatabase.com/cve/CVE-2025-23420
Use CWE-787, Openatom vendor hub and Openharmony product page to widen CVE-2025-23420 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-27577, CVE-2025-27128 and CVE-2025-12736 for nearby disclosures in the same product family.