Junglewise Threat Intelligence

CVE-2025-67316: realme Internet Browser improper access control in WebView interface

CVE-2025-67316 · Severity: medium · CVSS 5.4 · Published 2026-01-05

Executive brief

A security vulnerability exists in the built-in web browser found on realme and ColorOS devices. By tricking a user into visiting a specially crafted website, an attacker can force the device to perform unauthorized actions, such as opening system settings or changing WiFi configurations without the user's permission. This could lead to unauthorized access to device features or disruption of the user's experience.

Technical details

The vulnerability stems from the improper use of the 'addJavascriptInterface()' method in the WebView component of the realme Internet browser v45.13.4.1. The application exposes privileged Android Java methods (such as openWifi, openSetting, and openSystemDateAndTime) to WebView JavaScript without implementing domain allowlists, URL scheme restrictions, or permission checks. A remote attacker can exploit this by hosting a malicious webpage that, when rendered by the affected browser, invokes these exposed Java methods to trigger unintended local application code and Android system activities. The vendor is reportedly disputing the finding.

Affected products

  • realme Internet Browser (HeyTap/ColorOS) 45.13.4.1

Timeline

  • 2026-01-05: advisory: Initial NVD publication
  • 2026-03-26: other: Supplier disputed the finding

References