Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xiaomi Mi A2 Lite 访问控制错误漏洞
Vulnerability Description
Xiaomi Mi A2 Lite是中国小米科技(Xiaomi)公司的一款智能手机。 Xiaomi Mi A2 Lite(build fingerprint:xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys)中的com.qualcomm.qti.callenhancement app存在安全漏洞。攻击者可利用该漏洞进行未授权的话筒录音。
CVSS Information
N/A
Vulnerability Type
N/A