An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser
References
| Link | Resource |
|---|---|
| http://internet.com | Broken Link |
| http://realme.com | Not Applicable |
| https://gist.github.com/Brucewebva/ceb365b7cea0d0b8ec0ce6755177de83 | Exploit Third Party Advisory |
Configurations
History
30 Jan 2026, 01:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Heytap
Heytap internet Browser |
|
| CPE | cpe:2.3:a:heytap:internet_browser:45.13.4.1:*:*:*:*:*:*:* | |
| References | () http://internet.com - Broken Link | |
| References | () http://realme.com - Not Applicable | |
| References | () https://gist.github.com/Brucewebva/ceb365b7cea0d0b8ec0ce6755177de83 - Exploit, Third Party Advisory |
05 Jan 2026, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
05 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-05 17:15
Updated : 2026-01-30 01:25
NVD link : CVE-2025-67316
Mitre link : CVE-2025-67316
CVE.ORG link : CVE-2025-67316
JSON object : View
Products Affected
heytap
- internet_browser
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
