Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mi
Subscribe
|
Redmi 4a
Subscribe
Redmi 4a Firmware
Subscribe
Redmi 5 Plus
Subscribe
Redmi 5 Plus Firmware
Subscribe
Redmi 6
Subscribe
Redmi 6 Firmware
Subscribe
Redmi 6a
Subscribe
Redmi 6a Firmware
Subscribe
Redmi 7
Subscribe
Redmi 7 Firmware
Subscribe
Redmi 7a
Subscribe
Redmi 7a Firmware
Subscribe
Redmi Go
Subscribe
Redmi Go Firmware
Subscribe
Redmi K20
Subscribe
Redmi K20 Firmware
Subscribe
Redmi K20 Pro
Subscribe
Redmi K20 Pro Firmware
Subscribe
Redmi Note 4
Subscribe
Redmi Note 4 Firmware
Subscribe
Redmi Note 5
Subscribe
Redmi Note 5 Firmware
Subscribe
Redmi Note 5 Pro
Subscribe
Redmi Note 5 Pro Firmware
Subscribe
Redmi Note 5a Prime
Subscribe
Redmi Note 5a Prime Firmware
Subscribe
Redmi Note 6 Pro
Subscribe
Redmi Note 6 Pro Firmware
Subscribe
Redmi Note 7
Subscribe
Redmi Note 7 Firmware
Subscribe
Redmi Note 7s
Subscribe
Redmi Note 7s Firmware
Subscribe
Redmi S2
Subscribe
Redmi S2 Firmware
Subscribe
Redmi Y3
Subscribe
Redmi Y3 Firmware
Subscribe
Stock Browser
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-13077 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:05:17.321Z
Reserved: 2018-12-27T00:00:00.000Z
Link: CVE-2018-20523
No data.
Status : Modified
Published: 2019-06-07T16:29:00.440
Modified: 2024-11-21T04:01:39.083
Link: CVE-2018-20523
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD