VulnerabilityModified
CVE-2018-20523
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection.
MEDIUM 5.3EPSS 10.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.0%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 10.01% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- mi/stock browser · mi/redmi 7 firmware · mi/redmi note 7 firmware · mi/redmi note 6 pro firmware · mi/redmi 6 firmware · mi/redmi 6a firmware · mi/redmi s2 firmware · mi/redmi note 5 pro firmware · mi/redmi k20 pro firmware · mi/redmi k20 firmware · mi/redmi 7a firmware · mi/redmi go firmware · mi/redmi note 5 firmware · mi/redmi y3 firmware · mi/redmi note 7s firmware · mi/redmi 4a firmware · mi/redmi note 4 firmware · mi/redmi 5 plus firmware · mi/redmi note 5a prime firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/163796/Xiaomi-10.2.4.g-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://sec.xiaomi.comBroken Link, Vendor Advisory
- https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-in-xiaomi-stock-browserExploit, Third Party Advisory
- http://packetstormsecurity.com/files/163796/Xiaomi-10.2.4.g-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://sec.xiaomi.comBroken Link, Vendor Advisory
- https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-in-xiaomi-stock-browserExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.