Heytap develops a web browser product that represents a focused but disproportionately visible attack surface in the landscape; the observed vulnerability pattern centers on cross-site scripting and related input-neutralization weaknesses characteristic of browser rendering engines. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Heytap over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67316MEDIUM An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier | Jan 5, 2026 | 5.4 | 23 | NO | NO |
CVE-2024-23729MEDIUM The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBr | Aug 19, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Heytap.
Media articles that mention a CVE ID that affects a product developed by Heytap — matched by CVE ID, not by vendor name.