A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint Browser 1.5.3 due to the way they handle the q query parameter. The portion of an https URL before the ?q= substring is not shown to the user.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mi_browser | Mi | 10.5.6-g (including) | 10.5.6-g (including) |
Mint_browser | Mi | 1.5.3 (including) | 1.5.3 (including) |