OpenHarmony Local Arbitrary Code Execution Vulnerability in Pre-Installed Apps

Vulnerability

A use-after-free vulnerability allowing local attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions through 5.0.2. This issue can only be exploited under certain restricted conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized arbitrary code execution within pre-installed applications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.