CVE-2024-23727: Kamivision Yi IoT

High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.

Affected products

  • Kamivision Yi IoT: up to and including 1.0.0_20231219

Published 2024-03-28. Last modified 2026-06-17.