OpenHarmony Arbitrary Code Execution Vulnerability in Pre-Installed Apps

Vulnerability

A vulnerability allowing remote attackers to execute arbitrary code in pre-installed applications has been identified in OpenHarmony versions 6.0 and prior. This issue arises from a buffer overflow vulnerability in the 'web_webview' component, which is part of the Chromium web engine used by OpenHarmony.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code within the context of the affected application.

Remediation

Users can apply the available patches by merging the '6.0.x' branch for OpenHarmony 6.0 and the '5.1.0.x' or '5.0.3.x' branches for OpenHarmony 5.1.0 and 5.0.3, respectively.

Added: May 19, 2026, 4:34 AM
Updated: May 19, 2026, 4:34 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
3.6
remediation
7.7
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.