CVE-2025-25277: arkcompiler_ets_runtime has a type confusion vulnerability
Published Mar 16, 2026
·Updated
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.
Affected Software
3 affected components
OpenHarmony arkcompiler_ets_runtime<=5.1.0
Openatom Openharmony=5.0.3
Openatom Openharmony=5.1.0
Event History
Mar 16, 2026
CVE Published
via MITRE·07:09 AM
Data Sourced
via MITRE·07:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25277?
CVE-2025-25277 is a type confusion vulnerability that allows for arbitrary code execution in pre-installed apps.
2
How do I fix CVE-2025-25277?
To mitigate CVE-2025-25277, update your OpenHarmony to version 5.1.1 or later, where the vulnerability has been addressed.
3
Who is affected by CVE-2025-25277?
CVE-2025-25277 affects users running OpenHarmony versions 5.0.3 and 5.1.0.
4
What type of attacks can CVE-2025-25277 enable?
CVE-2025-25277 can enable local attackers to execute arbitrary code on vulnerable devices.
5
In what scenarios can CVE-2025-25277 be exploited?
CVE-2025-25277 can be exploited only in restricted scenarios involving incompatible types in the arkcompiler_ets_runtime.