First published: Mon Mar 04 2024(Updated: )
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openatom Openharmony | >=3.2<=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46708 is a high-severity vulnerability that allows local attackers arbitrary code execution in apps.
To fix CVE-2023-46708, upgrade to OpenHarmony version 3.2.5 or later.
CVE-2023-46708 affects all users of OpenHarmony version 3.2.4 and prior versions.
CVE-2023-46708 is caused by a use-after-free error that allows for arbitrary code execution.
CVE-2023-46708 cannot be exploited remotely as it requires local access to the affected system.