PT-2019-14200 · Xiaomi+1 · Xiaomi Mi Mix 2S+1

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15471

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys com.qualcomm.qti.callenhancement app version 8.1.0
Description The issue allows pre-installed apps with signatureOrSystem permissions to access the microphone for audio recording via an accessible component of the com.qualcomm.qti.callenhancement app. This capability can be exploited by any pre-installed app on the device to record telephone calls to external storage.
Recommendations For the Xiaomi Mi Mix 2S Android device, consider disabling the com.qualcomm.qti.callenhancement app until a patch is available. For the com.qualcomm.qti.callenhancement app version 8.1.0, restrict access to its open interface to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15471

Affected Products

Xiaomi Mi Mix 2S
Com.Qualcomm.Qti.Callenhancement