vendor:
Mi Browser
by:
Vishwaraj101
5,3
CVSS
MEDIUM
Content Provider Injection
200
CWE
Product Name: Mi Browser
Affected Version From: 10.2.4.g
Affected Version To: 10.2.4.g
Patch Exists: YES
Related CWE: CVE-2018-20523
CPE: a:xiaomi:mi_browser:10.2.4.g
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Android
2018
Xiaomi browser 10.2.4.g – Browser Search History Disclosure
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones were vulnerable to content provider injection using which any 3rd party application can read the user’s browser history.
Mitigation:
The vulnerability was fixed in the latest version of the Xiaomi browser.