OpenHarmony Information Leak Vulnerability Allowing Local Attackers to Access Sensitive Data

Vulnerability

A vulnerability in OpenHarmony versions 6.0 and prior allows local attackers to leak sensitive information due to improper permission management in the filemanagement_storage_service component.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information.

Remediation

Users can apply the available patches for this vulnerability in the OpenHarmony-v6.0-Release and OpenHarmony-v5.1.0-Release versions. Instructions for applying the patch can be found in the OpenHarmony filemanagement_storage_service repository.

Added: May 19, 2026, 4:33 AM
Updated: May 19, 2026, 4:33 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
3.3
remediation
0.0
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.