Impact
The filemanagement_storage_service in OpenHarmony incorrectly preserves file permissions, allowing a local attacker to read data that should have been protected. This flaw is associated with CWE-281 and results in the leakage of sensitive information stored on the device.
Affected Systems
OpenHarmony OpenHarmony v6.0 and all earlier releases are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.5, indicating moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector is local; no remote exploitation is described. Because only users with local access can trigger the information leak, the risk is confined to compromised or compromised locally isolated environments.
OpenCVE Enrichment