A backdoor on Xiaomi device allows silent and remote deliver of any app

General News

Summary

A Dutch Computer Science student, Thijs Broenink, who analyzed his Xiaomi mobile device discovered the presence of a backdoor that could allow an attacker to silently install any app on the phone. In August 2014, experts at F-Secure security firm analyzing the new Xiaomi RedMi 1S discovered that it was sending out to a server located in China a lot of user’s data. The app sends out mobile device identification data including Model, IMEI, MAC address, Nonce, Package name as well as signature. Broenink discovered that the update process implemented by Xiaomi lack of validation, this means that hackers can exploit it to deliver a malicious software on the smartphone. The student hasn’t discovered the real purpose of the AnalyticsCore app, it sounds like a sort of backdoor that opens million Xiaomi devices to cyber attack.

Classifications

industries
Fintech & Banking
applications
Networking and Cloud

AskAI Classifications

Labels
No AI classifications detected

Linked Companies