PT-2019-14199 · Xiaomi+1 · Xiaomi Redmi Note 6 Pro+1

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15470

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys
Description The issue allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device that can obtain signatureOrSystem permissions. The app enables a third-party app to use its open interface to record telephone calls to external storage.
Recommendations For the Xiaomi Redmi Note 6 Pro Android device, consider disabling the com.qualcomm.qti.callenhancement app until a patch is available to prevent other pre-installed apps from accessing its capabilities. Restrict access to the microphone audio recording feature to minimize the risk of unauthorized recording. Avoid using the device for sensitive conversations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15470

Affected Products

Android
Xiaomi Redmi Note 6 Pro