OpenHarmony
cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*
- >= 5.0.3-Release, <= 5.0.3-Release
- >= 5.1.0-Release, <= 5.1.0-Release
A vulnerability in OpenHarmony versions through 5.1.0 that allows local attackers to execute arbitrary code in pre-installed applications. This issue arises from an out-of-bounds write vulnerability and can only be exploited in certain restricted scenarios.
Exploitation of this vulnerability could lead to arbitrary code execution in the context of the affected application.
Users can apply the available patches for this vulnerability in the OpenHarmony-5.1.0-Release and OpenHarmony-5.0.3-Release branches. Instructions for applying the patch can be found in the OpenHarmony security disclosure for October 2025.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.