Skip to main content

NULL Pointer Dereference

CVE-2025-21084

Severity Low
Score 3.8/10

Summary

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.

  • LOW
  • LOCAL
  • NONE
  • CHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-476 - NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

References

Advisory Timeline

  • Published