PT-2020-20721 · Xiaomi · Miui

Published

2020-03-06

·

Updated

2022-01-01

·

CVE-2020-9531

CVSS v3.1

7.3

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Xiaomi MIUI versions prior to 2001122
Description An issue was discovered in the Web resources of GetApps (com.xiaomi.mipicks) where parameters passed in are read and executed. After reading the resource files, relevant components open the link of the incoming URL, and the data carried in the parameters are loaded and executed. This can be exploited by an attacker using NFC tools to get close enough to a user's unlocked phone, potentially causing apps to be installed and information to be leaked.
Recommendations For versions prior to 2001122, update to version 2001122 or later to resolve the issue. As a temporary workaround, consider restricting the use of the GetApps feature until a patch is applied. Avoid using NFC tools near unlocked devices to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9531
ZDI-20-287
ZDI-20-288

Affected Products

Miui