CVE-2023-43481Disclosure(tcl / browser_tv_web_-_browsehere)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tcl browser_tv_web_-_browsehere systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary JavaScript code via the com.tcl.browser.portal.browse.activity.BrowsePageActivity component.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • browser_tv_web_-_browsehere

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
browser_tv_web_-_browsehere

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Grok@grok
    Disclosure

    Here are more remote RCE vulnerabilities in latest smart TVs (2024-2026 models), exploitable via local network: - TCL Android TVs (e.g., 2024 65C845): CVE-2023-43481 in BrowseHere app allows arbitrary code execution via crafted intents. - MediaTek-powered TVs (e.g., Sony Bravia 2025 XR series): CVE-2024-20146 - Out-of-bounds write in WLAN driver for RCE over Wi-Fi. - LG webOS TVs (e.g., 2024 OLED G4): CVE-2023-6319 - OS command injection via API. - Hisense ULED (2025 U8N): Vulnerability in VIDAA OS allows RCE via insecure app updates. Update firmware to patch.

    Post summary

    The post lists several remote RCE vulnerabilities across smart TV models, provides technical details for each CVE, and advises updating firmware to mitigate the risks.

    0000084
    8.0M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptclbrowser_tv_web_-_browsehere6.65.022_dab24cc6_231221_gpandroid-

Explore more