OpenHarmony Information Leak Vulnerability in Multimedia Audio Standard Component

Vulnerability

A vulnerability allowing case-sensitive information leakage has been identified in the OpenHarmony operating system, specifically in version 5.0.3 and earlier. This issue arises from the use of uninitialized resources, which local attackers could exploit under certain conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users can apply the available patch by merging the corresponding pull request into their OpenHarmony version. Instructions for this can be found in the OpenHarmony GitHub repository.

Added: Mar 16, 2026, 2:53 PM
Updated: Mar 16, 2026, 2:53 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.