First published: Fri Jun 07 2019(Updated: )
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mi Stock Browser | =10.2.4g | |
Mi Redmi 7 Firmware | ||
Mi Redmi 7 | ||
Mi Redmi Note 7 Firmware | ||
Mi Redmi Note 7 | ||
Mi Redmi Note 6 Pro Firmware | ||
mi Redmi Note 6 Pro | ||
Mi Redmi 6 Firmware | ||
mi Redmi 6 | ||
Mi Redmi 6a Firmware | ||
Mi Redmi 6a | ||
Mi Redmi S2 Firmware | ||
Mi Redmi S2 | ||
Mi Redmi Note 5 Pro Firmware | ||
mi Redmi Note 5 Pro | ||
Mi Redmi K20 Pro Firmware | ||
Mi Redmi K20 Pro | ||
Mi Redmi K20 Firmware | ||
Mi Redmi K20 | ||
Mi Redmi 7a Firmware | ||
Mi Redmi 7a | ||
Mi Redmi Go Firmware | ||
Mi Redmi Go | ||
Mi Redmi Note 5 Firmware | ||
mi Redmi Note 5 | ||
Mi Redmi Y3 Firmware | ||
Mi Redmi Y3 | ||
Mi Redmi Note 7s Firmware | ||
Mi Redmi Note 7s | ||
Mi Redmi 4a Firmware | ||
Mi Redmi 4a | ||
Mi Redmi Note 4 Firmware | ||
Mi Redmi Note 4 | ||
Mi Redmi 5 Plus Firmware | ||
Mi Redmi 5 Plus | ||
Mi Redmi Note 5a Prime Firmware | ||
Mi Redmi Note 5a Prime |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.