Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xiaomi Mi Mix 2S 访问控制错误漏洞
Vulnerability Description
Xiaomi Mi Mix 2S是中国小米科技(Xiaomi)公司的一款智能手机。 Xiaomi Mi Mix 2S(build fingerprint:Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys)中的com.qualcomm.qti.callenhancement app存在访问控制错误漏洞。攻击者可借助第三方软件利用该漏洞进行未授权的话筒录音。
CVSS Information
N/A
Vulnerability Type
N/A