ZDI-CAN-7467: (Pwn2Own) Xiaomi Browser Captive Portal WebView Authorization Bypass Vulnerability
This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Mi6. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw exists within the handling of HTTP responses to the Captive Portal. A crafted HTML response can cause the Captive Portal to to open a browser to a specified location without user interaction. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-7467?
The severity of ZDI-CAN-7467 is critical as it allows arbitrary code execution through a malicious access point.
How do I fix ZDI-CAN-7467?
To fix ZDI-CAN-7467, ensure to update your Xiaomi browser and apply any available security patches.
Who is affected by ZDI-CAN-7467?
ZDI-CAN-7467 affects users of the Xiaomi browser on devices like the Xiaomi Mi6.
What type of attackers can exploit ZDI-CAN-7467?
Network adjacent attackers can exploit ZDI-CAN-7467 by tricking users into connecting to malicious access points.
Is user interaction required for ZDI-CAN-7467 exploitation?
Yes, user interaction is required for ZDI-CAN-7467 since the target must connect to a malicious access point.