Vulnerability Details CVE-2018-20523
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.072
EPSS Ranking 91.1%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-20523
-
cpe:2.3:a:mi:stock_browser:10.2.4g
-
-
cpe:2.3:h:mi:redmi_5_plus:-
-
-
-
-
-
-
-
cpe:2.3:h:mi:redmi_k20_pro:-
-
cpe:2.3:h:mi:redmi_note_4:-
-
cpe:2.3:h:mi:redmi_note_5:-
-
cpe:2.3:h:mi:redmi_note_5_pro:-
-
cpe:2.3:h:mi:redmi_note_5a_prime:-
-
cpe:2.3:h:mi:redmi_note_6_pro:-
-
cpe:2.3:h:mi:redmi_note_7:-
-
cpe:2.3:h:mi:redmi_note_7s:-
-
-
-
cpe:2.3:o:mi:redmi_4a_firmware:-
-
cpe:2.3:o:mi:redmi_5_plus_firmware:-
-
cpe:2.3:o:mi:redmi_6_firmware:-
-
cpe:2.3:o:mi:redmi_6a_firmware:-
-
cpe:2.3:o:mi:redmi_7_firmware:-
-
cpe:2.3:o:mi:redmi_7a_firmware:-
-
cpe:2.3:o:mi:redmi_go_firmware:-
-
cpe:2.3:o:mi:redmi_k20_firmware:-
-
cpe:2.3:o:mi:redmi_k20_pro_firmware:-
-
cpe:2.3:o:mi:redmi_note_4_firmware:-
-
cpe:2.3:o:mi:redmi_note_5_firmware:-
-
cpe:2.3:o:mi:redmi_note_5_pro_firmware:-
-
cpe:2.3:o:mi:redmi_note_5a_prime_firmware:-
-
cpe:2.3:o:mi:redmi_note_6_pro_firmware:-
-
cpe:2.3:o:mi:redmi_note_7_firmware:-
-
cpe:2.3:o:mi:redmi_note_7s_firmware:-
-
cpe:2.3:o:mi:redmi_s2_firmware:-
-
cpe:2.3:o:mi:redmi_y3_firmware:-