OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps

Vulnerability

A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This vulnerability can only be exploited in certain restricted scenarios.

Impact

Exploitation of this vulnerability could lead to unauthorized arbitrary code execution within pre-installed applications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.