Vulnerability Description
An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier is currently disputing this finding and the record is under review.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Heytap | Internet Browser | 45.13.4.1 |
Related Weaknesses (CWE)
References
- http://internet.comBroken Link
- http://realme.comNot Applicable
- https://gist.github.com/Brucewebva/ceb365b7cea0d0b8ec0ce6755177de83ExploitThird Party Advisory
FAQ
What is CVE-2025-67316?
CVE-2025-67316 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier is currently disputi...
How severe is CVE-2025-67316?
CVE-2025-67316 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67316?
Check the references section above for vendor advisories and patch information. Affected products include: Heytap Internet Browser.