OpenHarmony
cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*
- >= 5.1.0, <= 5.1.0-Release
- >= 5.0.3, <= 5.0.3-Release
A vulnerability in the arkcompiler_ets_runtime component of OpenHarmony has been identified, allowing local attackers to execute arbitrary code in pre-installed applications. This issue arises from an out-of-bounds write and is present in OpenHarmony versions through 5.1.0. The vulnerability can only be exploited in restricted scenarios.
Exploitation of this vulnerability could lead to arbitrary code execution in the context of the affected application.
Users can apply the available patches in the OpenHarmony-5.1.0-Release and OpenHarmony-5.0.3-Release branches. Instructions for applying these patches can be found in the respective pull requests linked in the CVE details.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.