tlder@devCVE-2026-25781: Local Denial-of-Service Vulnerability Disclosed in OpenHarmony v6.0
tlder@dev:~$
Mobile/Android

CVE-2026-25781: Local Denial-of-Service Vulnerability Disclosed in OpenHarmony v6.0

  • Shipped
  • Action required
  • High importance

CVE-2026-25781 describes a local denial-of-service condition in OpenHarmony v6.0 with a CVSS score of 8.4, triggered through pre-installed application components. While it does not enable remote code execution, its severity score exceeds many RCE bugs due to the reliability and low complexity of the local trigger. For developers and device vendors supporting OpenHarmony-based hardware, this disclosure alongside two concurrent RCE CVEs signals a broader audit of the v6.0 pre-installed app layer. Waiting for an official OS security update is the correct remediation path; no app-level workaround is available for pre-installed system components.