ZDI-24-417: Xiaomi Pro 13 isUrlMatchLevel Permissive List of Allowed Inputs Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xiaomi Pro 13 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-26322.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-417?
ZDI-24-417 has a significant severity level as it allows remote attackers to execute arbitrary code on Xiaomi Pro 13 smartphones.
How do I fix ZDI-24-417?
To fix ZDI-24-417, ensure your Xiaomi Pro 13 smartphone is updated with the latest security patches provided by Xiaomi.
Who is affected by ZDI-24-417?
ZDI-24-417 affects users of the Xiaomi Pro 13 smartphone.
What types of attacks are possible with ZDI-24-417?
ZDI-24-417 allows remote code execution attacks requiring user interaction such as visiting a malicious page or opening a malicious file.
Is user interaction required to exploit ZDI-24-417?
Yes, user interaction is required to exploit ZDI-24-417 by having the target visit a malicious page or open a malicious file.