The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2023/2023-02.md