VulnerabilityModified
CVE-2020-14116
An intent redirection vulnerability in the Mi Browser product.
HIGH 7.5EPSS 0.44%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Affected
- mi/mi browser
- Source
- security@xiaomi.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.