Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Xiaomi Mi Pad 4 Android device with a build fingerprint of Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xiaomi Mi Pad 4 访问控制错误漏洞
Vulnerability Description
Xiaomi Mi Pad 4是中国小米科技(Xiaomi)公司的一款平板电脑。 Xiaomi Mi Pad 4(build fingerprint:Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys)中的com.qualcomm.qti.callenhancement app存在访问控制错误漏洞。攻击者可借助第三方软件利用该漏洞进行未授权的话筒录音。
CVSS Information
N/A
Vulnerability Type
N/A