Xiaomi · Xiaomi Stock Browser · CVE-2018-20523
Name of the Vulnerable Software and Affected Versions:
Xiaomi Stock Browser version 10.2.4.g
Description:
The issue allows a third-party application to read the user's cleartext browser history. This can be achieved via an `app.provider.query` request to the `content://com.android.browser.searchhistory/searchhistory` API endpoint.
Recommendations:
For Xiaomi Stock Browser version 10.2.4.g, consider restricting access to the `content://com.android.browser.searchhistory/searchhistory` API endpoint to prevent unauthorized reading of browser history. As a temporary workaround, users may want to avoid using the browser until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.