OpenHarmony WebView Component Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the OpenHarmony WebView component, specifically in versions through 6.0. This vulnerability allows attackers to execute arbitrary code in pre-installed applications.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the affected application.

Remediation

Users can apply the patch available in the OpenHarmony Chromium CEF repository, specifically in the pull request linked in the references.

Added: May 19, 2026, 4:36 AM
Updated: May 19, 2026, 4:36 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
4.3
remediation
7.7
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.