OpenHarmony Telephony Call Manager Module Permission Bypass Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability exists in the OpenHarmony telephony call manager module in versions through 5.0.3. This vulnerability allows local attackers to bypass permissions, leading to unauthorized access to sensitive information. The issue arises from improper permission handling, which can be exploited to access data that should be restricted.

Impact

Exploitation of this vulnerability can result in unauthorized access to sensitive information.

Remediation

Users can apply the available patch by updating to the OpenHarmony 5.0.3 release version. Instructions for applying the patch can be found in the OpenHarmony telephony call manager repository on Gitee.

Added: Jun 8, 2025, 12:19 PM
Updated: Jun 8, 2025, 12:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.