The security of Xiaomi’s mobile payment system is far from perfect; Check Point Research, a cyber threat intelligence research team released a report which revealed significant vulnerabilities in Xiaomi’s Mi-Pay.
Xiaomi is one of the leading smartphone manufacturers in China, and its products are increasingly popular globally. The company launched Mi-Pay in 2015 as a contactless payment method for Xiaomi users, which allows cashless transactions such as instant money transfers, linking bank accounts, paying bills, and more.
Check Point Research is a cyber threat intelligence research team that is part of the security firm Check Point Software Technologies. The group has published several reports on vulnerabilities in popular tech products, including Apple’s iOS operating system and the Android mobile platform.
According to the report, the vulnerabilities could have allowed attackers to access users’ Mi-Pay accounts and perform unauthorised transactions remotely.
The researchers found that the Xiaomi server was not verifying the source of requests, meaning that anyone could send requests to the server and access account information. The report showed that the Tencent Soter used by Xiaomi devices is compromised. Tencent Soter is the embedded mobile payment network used by Xiaomi to verify payment packages.
Check Point Research also found that trusted apps on Xiaomi can be downgraded. “We found that attacker can transfer an old version of a trusted app to the device and use it to overwrite the new app file,” says the report. This means that attackers may bypass any security fixes made by Xiaomi, thereby making them vulnerable.
After the report’s release, Xiaomi acknowledged the vulnerabilities presented and addressed the security concerns raised by Check Point Research.
The Check Point Research report serves as a reminder that even big tech companies are not immune to security threats and that users should always be vigilant about their online safety.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...