Xiaomi Android Devices Hit by Multiple Flaws Across Apps and System Components
ID: 5138adce-999b-5e82-a454-22946db66dfb
STIX ID: report--5138adce-999b-5e82-a454-22946db66dfb
Feed Name: The Hacker News
Oversecured disclosed 20 security vulnerabilities across Xiaomi devices affecting system and vendor apps (Gallery, GetApps, Mi Video, Bluetooth, Phone Services, Print Spooler, Security components, Settings, ShareMe, System Tracing, Xiaomi Cloud, etc.). The flaws include a shell command injection, a memory-corruption bug originating from LiveEventBus, and misuse of implicit broadcasts that can leak Xiaomi account and phone data; they can enable access to privileged activities/services and arbitrary file theft. Issues were reported to Xiaomi in April 2023 and users are advised to apply updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
