Vulnerability Description
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mi | Stock Browser | 10.2.4g |
| Mi | Redmi 7 Firmware | - |
| Mi | Redmi 7 | - |
| Mi | Redmi Note 7 Firmware | - |
| Mi | Redmi Note 7 | - |
| Mi | Redmi Note 6 Pro Firmware | - |
| Mi | Redmi Note 6 Pro | - |
| Mi | Redmi 6 Firmware | - |
| Mi | Redmi 6 | - |
| Mi | Redmi 6A Firmware | - |
| Mi | Redmi 6A | - |
| Mi | Redmi S2 Firmware | - |
| Mi | Redmi S2 | - |
| Mi | Redmi Note 5 Pro Firmware | - |
| Mi | Redmi Note 5 Pro | - |
| Mi | Redmi K20 Pro Firmware | - |
| Mi | Redmi K20 Pro | - |
| Mi | Redmi K20 Firmware | - |
| Mi | Redmi K20 | - |
| Mi | Redmi 7A Firmware | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/163796/Xiaomi-10.2.4.g-Information-DisclosuExploitThird Party AdvisoryVDB Entry
- https://sec.xiaomi.comBroken LinkVendor Advisory
- https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-inExploitThird Party Advisory
- http://packetstormsecurity.com/files/163796/Xiaomi-10.2.4.g-Information-DisclosuExploitThird Party AdvisoryVDB Entry
- https://sec.xiaomi.comBroken LinkVendor Advisory
- https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-inExploitThird Party Advisory
FAQ
What is CVE-2018-20523?
CVE-2018-20523 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's clearte...
How severe is CVE-2018-20523?
CVE-2018-20523 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20523?
Check the references section above for vendor advisories and patch information. Affected products include: Mi Stock Browser, Mi Redmi 7 Firmware, Mi Redmi 7, Mi Redmi Note 7 Firmware, Mi Redmi Note 7.