OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps

Vulnerability

A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the affected application.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.