OpenHarmony Integer Overflow Vulnerability Allowing Arbitrary Code Execution in Pre-Installed Apps

Vulnerability

A vulnerability in OpenHarmony versions through 5.0.2 allows local attackers to execute arbitrary code in pre-installed applications due to the presence of an integer overflow. This vulnerability arises from improper handling of integer values, which can be exploited to manipulate memory and execute unauthorized code.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within pre-installed applications, potentially allowing attackers to perform malicious actions or access sensitive data through these applications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.