CVE-2018-20523: Command Injection
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20523?
The severity of CVE-2018-20523 is classified as a high risk due to its ability to expose sensitive user information.
How do I fix CVE-2018-20523?
To mitigate the issue associated with CVE-2018-20523, users should update the Xiaomi Stock Browser to the latest version provided by Xiaomi.
Which devices are impacted by CVE-2018-20523?
CVE-2018-20523 affects Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro and other affected Redmi Android phones.
What type of vulnerability is CVE-2018-20523?
CVE-2018-20523 is classified as a content provider injection vulnerability that allows unauthorized access to user's browser history.
Can third-party applications exploit CVE-2018-20523?
Yes, third-party applications can exploit CVE-2018-20523 to read a user's cleartext browser history.