Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-67316

23
FAUCET Score

CVE-2025-67316 describes a cross-site scripting (CWE-79) vulnerability in realme Internet browser v.45.13.4.1, specifically within the built-in HeyTap/ColorOS browser component. This medium-severity vulnerability (CVSS 5.4) allows a remote attacker to execute arbitrary code by enticing a user to visit a specially crafted webpage. While the vulnerability is not currently listed on CISA's KEV catalog and lacks public exploit intelligence (Metasploit, Nuclei, ExploitDB), its FAUCET Risk Score of 76/100 indicates a notable potential risk. There is currently no evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
45.13.4.1CPE matchmatch criteria
cpe:2.3:a:heytap:internet_browser:45.13.4.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 15th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

c.realme.com / in/post-details/1171957723898576896
gist.github.com / Brucewebva/ceb365b7cea0d0b8ec0ce6755177de83
ExploitThird Party Advisory