CVE-2025-24301: Arkcompiler Ets Runtime has an UAF vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24301?
CVE-2025-24301 has been rated as a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-24301?
To fix CVE-2025-24301, update OpenHarmony to version 5.0.3 or later where the vulnerability has been patched.
Who is impacted by CVE-2025-24301?
Local users of OpenHarmony versions 5.0.2 and earlier are impacted by CVE-2025-24301.
What are the risks associated with CVE-2025-24301?
The risks associated with CVE-2025-24301 include unauthorized access and execution of malicious code within pre-installed applications.
In what scenarios can CVE-2025-24301 be exploited?
CVE-2025-24301 can be exploited in restricted scenarios where a local attacker can manipulate memory management.