OpenHarmony arkcompiler_ets_runtime Arbitrary Code Execution Vulnerability

Vulnerability

A vulnerability in the OpenHarmony arkcompiler_ets_runtime component, present in versions through 5.1.0, allows local attackers to execute arbitrary code in pre-installed applications by using incompatible types. This issue can only be exploited in specific, restricted scenarios.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the affected application.

Remediation

Users can upgrade to OpenHarmony versions 5.1.0 or 5.0.3 to address this vulnerability.

Added: Mar 16, 2026, 2:46 PM
Updated: Mar 16, 2026, 2:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
8.1
exploitability
2.3
remediation
7.7
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.