‘Security’ app on Xiaomi phones has dangerous security flaw: Check Point

Main Image
  • Like
  • Comment
  • Share

Xiaomi has sold millions of smartphones in India in the past few years and has even managed to attain number one smartphone brand slot for straight 6 quarters, as per IDC reports. At the time when there is a tremendous demand for Xiaomi phones in India, a new report on a possible flaw in pre-installed default ‘Security’ app has been published by Israeli cyber-security research firm.

The cybersecurity firm Check Point recently discovered a flaw in a pre-installed app that was meant to detect and protect Xiaomi phones from malware attacks in the first place.

The report explains the security flaw in full details. According to the Check Point report, the traffic to and from ‘Guard Provider’ (com.miui.guardprovider) is not encrypted which leaves a potential to carry out a Man-in-the-Middle (MiTM) attack when connected to the same network.

The research firm identified the integration of Xiaomi’s pre-installed app uses three different third-party Software Development Kits namely Avast, AVL and Tencent. Out of the three Avast and AVL are antivirus protection while Tencent SDK cleans and boosts phones performance.

ALSO READ: Samsung Galaxy A20 is a subdued Galaxy A30 sibling priced at Rs. 12,490

The cause of potential threat here is that all three apps are bundled together, therefore, they all share the same app permissions. The disadvantage of it is that if one SDK update is injected with a rogue code it could impact an attack on the other two SDKs as well.

The vulnerability has limited impact and should be fixed in a future update. But still, any attack based on this flaw could result in compromised inbound and outbound internet traffic. Lack of encryption also means an attacker could effectively gain control over the victim’s phone. Xiaomi is yet to release a statement on this issue. Once Xiaomi puts out a statement in public we will add it to this report.

Deepak RajawatDeepak Rajawat
Deepak Rajawat is a technology journalist and editor with over 12 years of experience in both print and digital media. Before transitioning to online journalism, he contributed to renowned publications including Hindustan Times and The Statesman.

At Smartprix, Deepak reviews smartphones, laptops, TVs, and soundbars, with a focus on answering the real-world questions that matter most to consumers. Over the past decade, he has reviewed more than 1,000 devices, combining hands-on expertise with a user-first approach.

A graduate in Journalism and Mass Communication from Calcutta University, Deepak also follows emerging technologies closely—including Virtual Reality (VR), Augmented Reality (AR), and Mixed Reality (MR). Earlier in his career, he covered sports with the same passion he now brings to tech.

He is based in Noida and joined Smartprix in September 2015.

Related Articles

ImageAnother OnePlus Handset Is Headed For India (Dubbed OnePlus 15R), Could Launch In December 2025

At the OnePlus 15‘s launch event, the company cleverly plugged in a teaser for another phone’s launch: the OnePlus 15R. Call it a teaser for the phone, but the company confirmed its existence. Now, an Indian tipster has predicted the launch timeline for the more affordable version of the OnePlus 15. Also Read: OnePlus 15, …

ImageXiaomi phones to be thrown away says Lithuania Defence Ministry; Company Dismisses Content censoring Allegations

In recent research conducted by Lithuania Defence Ministry, Xiaomi phones have been found to have built-in censorship capabilities. The National Cyber Security Centre of Lithuania claims that Mi 10T 5G’s inbuilt capability had been found turned off for the European Union Region but could be turned on anytime they wanted. Following this, the Lithuania ministry …

ImageIndia Bans Mi Browser Pro over data privacy concerns

The government of India has been gunning for Chinese apps ever since the Indo-china clash in the Ladakh region. Since then the Indian government has banned 59 Chinese apps followed by 47 more apps. Today, the Modi government has slapped a ban on Xiaomi’s Mi Browser Pro app in the country. The government points to …

ImageXi Jinping’s Spying Joke About Xiaomi Phones Goes Viral After Meeting South Korea’s Lee

The unusual exchange took place on Saturday in the historic city of Gyeongju, South Korea, during the sidelines of the APEC summit, marking Xi’s first visit to the country in more than a decade. According to local media reports, Xi presented President Lee with two Xiaomi smartphones, each fitted with Korean-made displays. As the two …

ImageiOS 26 & iPadOS 26 Stable Updates Announced: Check Release Date, New Features, & How To Install Here

The iPhone 17 series is official, and so is the iOS 26 stable update, which will soon be available for the compatible iPhone models. With the Liquid Glass design language, additions to the system apps like Messages, Phone, Camera, a revamped lock screen, and minor tweaks to other menus and layouts, iOS 26 is one …

Discuss

Be the first to leave a comment.