Impact
The vulnerability is a type confusion in the OpenHarmony arkcompiler ETS runtime. Vendor notes indicate that using an incompatible type allows a local attacker to execute arbitrary code within pre‑installed applications, leading to potential privilege escalation on the device.
Affected Systems
The flaw exists in OpenHarmony 5.0.3, 5.1.0, and all earlier releases prior to 5.1.0. All devices running these versions of the operating system are affected if they contain the default pre‑installed apps.
Risk and Exploitability
The CVSS base score is 6.3, reflecting moderate severity. The EPSS score is below 1% and the issue is not listed in CISA's KEV catalog. The attack vector is strictly local, requiring access to the device and the ability to trigger the type confusion within a pre‑installed application, which limits exploitation to restricted scenarios.
OpenCVE Enrichment