logo

Xiaomi Android Devices Hit by Multiple Flaws Across Apps and System Components

ID: 5138adce-999b-5e82-a454-22946db66dfb

STIX ID: report--5138adce-999b-5e82-a454-22946db66dfb

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-06

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Oversecured disclosed 20 security vulnerabilities across Xiaomi devices affecting system and vendor apps (Gallery, GetApps, Mi Video, Bluetooth, Phone Services, Print Spooler, Security components, Settings, ShareMe, System Tracing, Xiaomi Cloud, etc.). The flaws include a shell command injection, a memory-corruption bug originating from LiveEventBus, and misuse of implicit broadcasts that can leak Xiaomi account and phone data; they can enable access to privileged activities/services and arbitrary file theft. Issues were reported to Xiaomi in April 2023 and users are advised to apply updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.