← Vulnerability feed

Vulnerability record · CVE-2025-25277 · published 16 March 2026

CVE-2025-25277: Openatom openharmony type confusion vulnerability

Openatom · Openharmony

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.

7.0 CVSS 3.1 High EPSS 0.15% · top 96.4% CWE-843 · Type confusion
7.0CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-25277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-37077Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.EPSS 0.62%9.8CVE-2024-37185Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.EPSS 0.62%9.8CVE-2024-36243Openatom openharmony out-of-bounds read vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.EPSS 0.57%9.8CVE-2024-36260Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.EPSS 0.57%9.8CVE-2024-37030Openatom openharmony use after free vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.EPSS 0.57%8.8CVE-2025-22851Openatom openharmony integer overflow vulnerabilityin OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.EPSS 0.18%8.8CVE-2024-47398Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.EPSS 0.16%8.8CVE-2024-29074Openatom openharmony improper input validation vulnerabilityin OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2025-25277), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.