CVE-2019-10875 describes a URL spoofing vulnerability in Xiaomi Mi Browser (international versions 10.5.6-g) and Mint Browser (1.5.3). This flaw allows attackers to hide the true origin of an HTTPS URL by manipulating the "q" query parameter, potentially tricking users into believing they are on a legitimate site. With a CVSS score of 6.5 (Medium), the vulnerability requires user interaction (UI:R) but can lead to high integrity impact (I:H) through network-based attacks (AV:N). While there is no known active exploitation or publicly available exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5.6-gCPE matchmatch criteria | cpe:2.3:a:mi:mi_browser:10.5.6-g:*:*:*:*:*:*:* | ||
1.5.3CPE matchmatch criteria | cpe:2.3:a:mi:mint_browser:1.5.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.