CVE-2019-10875: Medium severity mi mi6 browser vulnerability
A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the "q" query parameter. The portion of an https URL before the ?q= substring is not shown to the user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10875?
CVE-2019-10875 is a URL spoofing vulnerability found in all international versions of Xiaomi Mi browser 10.5.6-g and Mint Browser 1.5.3.
How does CVE-2019-10875 affect the affected software?
CVE-2019-10875 allows an attacker to spoof URLs by manipulating the "q" query parameter in the affected browsers.
What is the severity of CVE-2019-10875?
The severity of CVE-2019-10875 is medium, with a severity value of 6.5.
How do I fix CVE-2019-10875?
To fix CVE-2019-10875, update Xiaomi Mi browser to version 10.6.1-g or later, and update Mint Browser to version 2.4.1 or later.
Are there any references for CVE-2019-10875?
Yes, you can find references for CVE-2019-10875 at the following links: [Packet Storm](http://packetstormsecurity.com/files/152497/Xiaomi-Mi-Browser-Mint-Browser-URL-Spoofing.html), [Xiaomi Security Response Center](https://sec.xiaomi.com/bug/5bedef67a31ec71e), and [The Hacker News](https://thehackernews.com/2019/04/xiaomi-browser-vulnerability.html).