CVE-2025-21082 is a type-confusion vulnerability in OpenHarmony 5.0.3 and earlier versions. A local attacker can exploit the type confusion to cause applications to crash.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is an educational security project centered on CVE-2025-21082, presented as a HyperOS AVCodec use-after-free vulnerability simulation, but it also retains a separate Python PoC for CVE-2025-2844 directory traversal. The repo is not part of a known exploit framework. Structure-wise, it contains: (1) a Rust CLI PoC in poc_rust/src/main.rs, which is the main artifact and simulates a UAF race using Arc<Mutex<CodecContext>>, a worker thread, and a release() routine that nulls/frees an internal buffer and flips a magic value to 0xFEEDFACE; (2) a Python PoC in poc_python/exploit.py that performs a real HTTP GET against /api/themes/download with a traversal payload in the theme parameter; (3) extensive Markdown documentation under docs/ describing the vulnerability, architecture, mitigations, and educational walkthroughs; and (4) HTML visualizations in simulation.html and assets/infographic.html. Main exploit capabilities: the Rust code does not deliver code execution or a shell; it is a local demonstrator that shows the vulnerable timing pattern and prints UAF detection when the worker thread observes corrupted state. In vulnerable mode, the main thread sleeps briefly, calls release(), and the worker later calls process_frame(), which detects the corrupted magic and reports the simulated UAF. In patched mode, the program joins the worker before release, demonstrating the mitigation. The Python code is more directly exploit-like: it builds ../../../{target_file}, optionally URL-encodes it, and requests {target_url}/api/themes/download?theme=..., aiming to read arbitrary files such as etc/shadow or var/hyperos/secret_key.pem. Assessment: this is a real PoC repository rather than a fake, but the primary Rust component is explicitly a simulation/educational demonstrator rather than a weaponized exploit. The Python script is an operational arbitrary-file-read PoC against a web endpoint if such a vulnerable service exists. Overall maturity is best classified as POC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.