First published: Fri Feb 02 2024(Updated: )
in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openatom Openharmony | >=3.2.0<=3.2.4 | |
Openatom Openharmony | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21860 is considered a critical vulnerability due to its potential for arbitrary code execution by adjacent attackers.
To fix CVE-2024-21860, update to OpenHarmony version 4.0.1 or later, or to a version beyond 3.2.4.
CVE-2024-21860 affects OpenHarmony versions 3.2.0 to 3.2.4 and version 4.0.0.
CVE-2024-21860 can be exploited by adjacent attackers who can gain access to the vulnerable application.
CVE-2024-21860 potentially allows attackers to execute arbitrary code within applications, leading to unauthorized actions.