First published: Tue Apr 02 2024(Updated: )
in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | <3.2.4 | |
Openatom Openharmony | >=3.2<=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22092 has a medium severity rating due to its ability to allow remote attackers to bypass permission verification.
To fix CVE-2024-22092, update OpenHarmony to a version later than v3.2.4.
CVE-2024-22092 affects users of OpenHarmony versions v3.2.4 and earlier.
CVE-2024-22092 allows a remote attacker to bypass permission verification for app installations, requiring user interaction.
CVE-2024-22092 was disclosed in April 2024.