CVE-2020-14121: Mi App Store

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.

Affected products

  • Mi Mi App Store: version 4.12.2 only

Published 2022-04-21. Last modified 2026-06-17.