CVE-2025-41432: arkcompiler_ets_runtime has an out-of-bounds write vulnerability
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41432?
CVE-2025-41432 is considered a medium severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-41432?
To fix CVE-2025-41432, update your OpenHarmony installation to version 5.1.1 or later where the vulnerability is patched.
Who is affected by CVE-2025-41432?
CVE-2025-41432 affects users of OpenHarmony versions up to and including 5.1.0.
What kind of attacks could be performed using CVE-2025-41432?
An attacker could exploit CVE-2025-41432 to execute arbitrary code in pre-installed applications on the affected systems.
Is CVE-2025-41432 exploit limited to certain environments?
Yes, CVE-2025-41432 can only be exploited in restricted scenarios, making it less likely to be a widespread issue.