Description
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Published: 2019-06-07
Score: 5.3 Medium
EPSS: 6.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-13077 Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
History

No history.

Subscriptions

Mi Redmi 4a Redmi 4a Firmware Redmi 5 Plus Redmi 5 Plus Firmware Redmi 6 Redmi 6 Firmware Redmi 6a Redmi 6a Firmware Redmi 7 Redmi 7 Firmware Redmi 7a Redmi 7a Firmware Redmi Go Redmi Go Firmware Redmi K20 Redmi K20 Firmware Redmi K20 Pro Redmi K20 Pro Firmware Redmi Note 4 Redmi Note 4 Firmware Redmi Note 5 Redmi Note 5 Firmware Redmi Note 5 Pro Redmi Note 5 Pro Firmware Redmi Note 5a Prime Redmi Note 5a Prime Firmware Redmi Note 6 Pro Redmi Note 6 Pro Firmware Redmi Note 7 Redmi Note 7 Firmware Redmi Note 7s Redmi Note 7s Firmware Redmi S2 Redmi S2 Firmware Redmi Y3 Redmi Y3 Firmware Stock Browser
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:05:17.321Z

Reserved: 2018-12-27T00:00:00.000Z

Link: CVE-2018-20523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-07T16:29:00.440

Modified: 2024-11-21T04:01:39.083

Link: CVE-2018-20523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses