Remote Code Execution Vulnerability in Xiaomi Mi6 Browser
CVE-2019-6743
7.8HIGH
What is CVE-2019-6743?
A vulnerability exists in Xiaomi Mi6 Browser that permits remote attackers to execute arbitrary code by leveraging a flaw in the WebAssembly.Instance method. This exploit requires user interaction, as the victim must either visit a malicious webpage or open a harmful file. The root of the issue lies in inadequate validation of data supplied by users, which may lead to a heap-based buffer overflow. By exploiting this vulnerability, an attacker can run code within the context of the affected process.
Affected Version(s)
Browser prior to 10.4.0