OpenHarmony Out-of-Bounds Write Vulnerability in Arkcompiler ETS Runtime Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing arbitrary code execution has been identified in OpenHarmony versions through 5.0.2. This issue arises from an out-of-bounds write in the arkcompiler_ets_runtime component, which can be exploited by local attackers in certain restricted scenarios, particularly within pre-installed applications.

Impact

Exploitation of this vulnerability could lead to unauthorized arbitrary code execution within the context of the affected application.

Remediation

Users can apply the available security patch by merging the pull request labeled '5.0.2.x' into their OpenHarmony 5.0.2 release branch.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.