CVE-2018-20523 - CVE House
Back to Database
Status published Medium CVE-2018-20523

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro...

Vulnerability Description

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20523

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stock browser, redmi 7 firmware, redmi note 7 firmware, redmi note 6 pro firmware, redmi 6 firmware, redmi 6a firmware, redmi s2 firmware, redmi note 5 pro firmware, redmi k20 pro firmware, redmi k20 firmware, redmi 7a firmware, redmi go firmware, redmi note 5 firmware, redmi y3 firmware, redmi note 7s firmware, redmi 4a firmware, redmi note 4 firmware, redmi 5 plus firmware, redmi note 5a prime firmware
Vulnerable Versions:
10.2.4g

Timeline

Official Publish: June 7th, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.