

Multiple security vulnerabilities have been identified in Xiaomi Android devices, affecting various apps and system components. According to a report by mobile security firm Oversecured, these flaws could lead to unauthorized access to system privileges, theft of files, and disclosure of sensitive user data including phone and Xiaomi account details. The vulnerabilities span across 20 different components, including Gallery, GetApps, Mi Video, and System Tracing.
Notable issues include a shell command injection in the System Tracing app and significant flaws in the Settings app that could expose Bluetooth and Wi-Fi connection details and emergency contacts. Additionally, a memory corruption issue was found in the GetApps app due to an unpatched Android library. Xiaomi has been informed of these vulnerabilities, and users are urged to update their devices to avoid potential security threats.