A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via the Wallpaper Carousel application to obtain sensitive Clipboard data and the user's stored credentials (partially). This occurs because of paste access to a social media login page.
References
Link | Resource |
---|---|
https://www.andmp.com/2019/04/unpatched-vulnerability-in-xiaomi-miui-os-lock-screen.html | Exploit Third Party Advisory |
https://www.andmp.com/2019/04/unpatched-vulnerability-in-xiaomi-miui-os-lock-screen.html | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 04:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.andmp.com/2019/04/unpatched-vulnerability-in-xiaomi-miui-os-lock-screen.html - Exploit, Third Party Advisory |
Information
Published : 2019-04-18 22:29
Updated : 2024-11-21 04:20
NVD link : CVE-2019-11015
Mitre link : CVE-2019-11015
CVE.ORG link : CVE-2019-11015
JSON object : View
Products Affected
miui
- miui
CWE
CWE-287
Improper Authentication