Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xiaomi Cepheus 访问控制错误漏洞
Vulnerability Description
Xiaomi Cepheus是中国小米科技(Xiaomi)公司的一款智能手机。 Xiaomi Cepheus(build fingerprint:Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys)中的com.qualcomm.qti.callenhancement app存在访问控制错误漏洞。攻击者可借助第三方软件利用该漏洞进行未授权的话筒录音。
CVSS Information
N/A
Vulnerability Type
N/A