漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xiaomi Mi A2 Lite 访问控制错误漏洞
Vulnerability Description
Xiaomi Mi A2 Lite是中国小米科技(Xiaomi)公司的一款智能手机。 Xiaomi Mi A2 Lite(build fingerprint:xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys)中的com.qualcomm.qti.callenhancement app存在访问控制错误漏洞。攻击者可利用该漏洞进行未授权的话筒录音。
CVSS Information
N/A
Vulnerability Type
N/A