OpenHarmony
cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*
- >= 5.0.3, < 5.0.4
- >= 6.0, < 6.1
A vulnerability allowing remote attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions 6.0 and prior. This issue arises from a buffer overflow vulnerability in the 'web_webview' component, which is part of the Chromium web engine used by OpenHarmony.
Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the affected application.
Users can apply the available patches by merging the '6.0.x' branch for OpenHarmony 6.0 and the '5.1.0.x' or '5.0.3.x' branches for OpenHarmony 5.1.0 and 5.0.3, respectively.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.