CVE-2026-24792: web_webview has a Race Condition vulnerability
Published May 19, 2026
·Updated
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
Affected Software
2 affected components
OpenHarmony OpenHarmony<=6.0
OpenHarmony web_webview<=6.0
Event History
May 19, 2026
CVE Published
via MITRE·02:58 AM
Data Sourced
via MITRE·02:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24792?
CVE-2026-24792 has a high severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-24792?
To fix CVE-2026-24792, update to the latest version of OpenHarmony that addresses this vulnerability.
3
What versions of OpenHarmony are affected by CVE-2026-24792?
CVE-2026-24792 affects all versions of OpenHarmony up to and including v6.0.
4
What type of vulnerability is CVE-2026-24792?
CVE-2026-24792 is classified as a Race Condition vulnerability.
5
Can CVE-2026-24792 be exploited remotely?
Yes, CVE-2026-24792 can be exploited remotely, allowing attackers to execute arbitrary code.