CVE-2020-9530: (Pwn2Own) Xiaomi Mi9 Browser manualUpgradeInfo Improper Control of Generation of Code Remote Code Execution Vulnerability
An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of opening other components. Attackers need to induce users to open specific web pages in a specific network environment. By jumping to the WebView component of Messaging(com.android.MMS) and loading malicious web pages, information leakage can occur. This is fixed on version: 2001122; 11.0.1.54.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xiaomi MIUIto a version that resolves this vulnerability.Fixed in 2001122 - Upgrade
Upgrade
Xiaomi MIUIto a version that resolves this vulnerability.Fixed in 11.0.1.54
Event History
Frequently Asked Questions
What is CVE-2020-9530?
CVE-2020-9530 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Xiaomi Mi9 Browser.
How can this vulnerability be exploited?
To exploit this vulnerability, the target must visit a malicious page or open a malicious file.
Which software versions are affected by CVE-2020-9530?
The affected software versions include Xiaomi Browser with MIUI Firmware 11.0.5.0.qfaeuxm.
What is the severity of CVE-2020-9530?
The severity of CVE-2020-9530 is high with a CVSS score of 8.8.
How can I fix CVE-2020-9530?
To mitigate CVE-2020-9530, it is recommended to update Xiaomi Mi9 Browser to the latest version provided by Xiaomi.