This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Xiaomi Mi9 Browser. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within Xiaomi GetApps webview. By manipulating HTML, an attacker can force a page redirection. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software | Affected Version | How to fix |
---|---|---|
Xiaomi Browser |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-9656 is classified as high due to its potential to allow arbitrary code execution.
To fix ZDI-CAN-9656, update your Xiaomi Mi9 Browser to the latest version provided by Xiaomi.
ZDI-CAN-9656 affects users of the Xiaomi Mi9 Browser who visit malicious pages or open malicious files.
Attackers can execute arbitrary code on affected installations of the Xiaomi Mi9 Browser if the user interacts with a malicious site or file.
Yes, user interaction is required for the exploitation of ZDI-CAN-9656, as the target must visit a malicious page or open a malicious file.