CVE-2019-13322 is a critical arbitrary code execution vulnerability affecting Xiaomi Browser versions prior to 10.4.0, specifically within the miui.share application's handling of user-supplied data. This flaw, rated 8.8 HIGH on CVSS, requires user interaction, such as visiting a malicious page, to trigger an arbitrary application download and subsequently execute code in the user's context. While the FAUCET Risk Score is 70/100, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.4.0CPE matchmatch criteria | cpe:2.3:a:mi:mi_browser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.