PT-2019-14200 · Xiaomi+1 · Xiaomi Mi Mix 2S+1
Published
2019-11-14
·
Updated
2020-08-24
·
CVE-2019-15471
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys
com.qualcomm.qti.callenhancement app version 8.1.0
Description
The issue allows pre-installed apps with signatureOrSystem permissions to access the microphone for audio recording via an accessible component of the com.qualcomm.qti.callenhancement app. This capability can be exploited by any pre-installed app on the device to record telephone calls to external storage.
Recommendations
For the Xiaomi Mi Mix 2S Android device, consider disabling the com.qualcomm.qti.callenhancement app until a patch is available.
For the com.qualcomm.qti.callenhancement app version 8.1.0, restrict access to its open interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xiaomi Mi Mix 2S
Com.Qualcomm.Qti.Callenhancement