CVE-2023-46708

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 4, 2024
Updated: Dec 16, 2024
CWE ID 416

Summary

CVE-2023-46708 is a vulnerability affecting OpenHarmony versions 3.2.4 and older. An attacker can exploit this issue by executing arbitrary code in any apps due to a use after free condition. This means that memory that has been freed is still being referenced, allowing an attacker to manipulate it and execute code of their choice. Successful exploitation could result in significant security risks, including data theft or system compromise. Users are strongly advised to update to the latest version of OpenHarmony to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share