First published: Fri Feb 07 2025(Updated: )
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | <4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0304 is considered a high severity vulnerability due to the potential for privilege escalation and sensitive information leakage.
To fix CVE-2025-0304, update OpenHarmony to version 4.1.3 or later, where the vulnerability is addressed.
CVE-2025-0304 affects all users of OpenHarmony versions up to 4.1.2.
CVE-2025-0304 is a use-after-free vulnerability that enables local attackers to escalate privileges.
An attacker exploiting CVE-2025-0304 can gain root privileges and potentially leak sensitive information.