Xiaomi's Mi Browser, Mint Browser Said to Contain Critical URL Spoofing Security Vulnerability

Advertisement
By Tasneem Akolawala | Updated: 5 April 2019 19:20 IST
Highlights
  • Mi Browser said to have URL spoofing flaw that hackers can exploit
  • Users can be duped into accessing malicious sites, due to URL spoofing
  • Xiaomi allegedly paid researcher for reporting issue, but left it unpatch

Xiaomi’s Mi Browser international variant only contains the vulnerability

Photo Credit: The Hacker News/ ANDMP

A new vulnerability has reportedly been discovered in Xiaomi's default pre-installed Mi Browser app and Mint Browser that essentially allows a malicious website to control URLs displayed in the address bar. The vulnerability has been allegedly been listed on Common Vulnerabilities and Exposures (CVE) database, but is in a "reserved state" for. It was discovered by security researcher Arif Khan. The researcher privately is said to have reported this vulnerability to Xiaomi, but it still hasn't been patched by the company. Xiaomi awarded Khan bug bounty, but decided to leave the issue unpatched. This browser flaw is said to affect only international variants, while China variants are allegedly safe.

The CVE-2019-10875 vulnerability is said to be a spoofing issue inside the address bar that exists because of a flaw in the browsers' interface. The vulnerability is said to exist both in the in-built Mi Browser on Xiaomi devices and in the Mint browser as well. Mint Browser can also be downloaded via Google Play by non-Xiaomi phone users. The Hacker News reports that the flaw can dupe users to thinking that they are visiting a trusted website, when they are actually visiting a site that served phishing or malicious content. This URL spoofing vulnerability allows hackers to bypass basic verifying indicators like URL and SSL.

Advertisement

This vulnerability only affects international variants of both the browsers, and the China variants do not contain this vulnerability. "The thing that struck me most was that only their overseas or, international versions were having this security bug and not their Chinese or, domestic versions. Was it done deliberately thus? Are Chinese device manufacturers intentionally making their OS, applications, and firmware vulnerable for their international users?" Arif told The Hacker News in an emailed statement. Khan has published proof of concept video, and it can be viewed below:


Khan also confirmed to the publication that Xiaomi rewarded him with a bug bounty (marginal amount of $99 for each browser) for reporting the issue that affects millions of users, but has chosen to leave the vulnerability unpatched. We've reached out to Xiaomi for comment on the issue, and will update this space when we hear back.

Advertisement

Android users, especially Xiaomi users, are highly recommended to avoid using the Mi browser. Modern web browsers like Chrome and Firefox should be used on smartphones. Xiaomi phones are immensely popular in India, with the company awarded the No.1 smartphone brand in 2018 by IDC. This vulnerability, and the company's lacklustre approach to resolving it, raises many questions.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: XIaomi, Mi Browser, Mint Browser
Advertisement

Related Stories

Popular Mobile Brands
  1. AI+ Nova 2 5G, Nova 2 Ultra 5G India Launch Date Announced; Design Teased
  2. Vivo X300 Ultra Camera Details Revealed as Handset Surfaces on Geekbench
  3. Samsung Galaxy A37, Galaxy A57 Price Details Emerge Ahead of March 25 Launch
  4. The Oppo Find X9 Ultra Might Launch in China, Global Markets on This Date
  5. Poco X8 Pro and Poco X8 Pro Max Go on Sale in India: See Price, Offers
  6. Apple Maps Could Soon Show Sponsored Listings
  7. Vivo V70 FE to Launch in India Soon With This 200-Megapixel Camera
  8. Apple TV, HomePod Mini Shortages Suggest New Models Might Arrive Soon
  9. Realme 16 5G Will Launch in India Soon With This Camera Setup
  10. Vivo X300s Leak Hints at Key Specifications Ahead of Launch Next Week
  1. Redmi Note 16 Series Tipped to Launch With Upgraded Battery, Similar Camera Hardware as Predecessor
  2. Honor 600 Pro, Honor 600 Leaked Renders Point to iPhone 17 Pro-Like Design; Tipped to Get 9,000mAh Battery
  3. Oppo Find X9 Ultra Tipped to Launch in China, Global Markets on April 20; India Debut Expected Later
  4. Vivo X300 Ultra Camera Details Leaked as Handset Surfaces on Geekbench Ahead of March 30 Launch
  5. iPhone Air’s C1X Chip Performs on Par With Qualcomm's Flagship X80 Modem, Ookla Says
  6. Vivo X300s Tipped to Launch With 50-Megapixel Selfie Camera, 90W Fast Charging Support
  7. Apple Maps to Soon Feature Ads on iPhone, More Devices As Apple Expands Service Revenue Strategy: Report
  8. Apple Announces WWDC 2026 for June 8; to Showcase Advancements in AI, Software
  9. Apple’s Foldable iPhone Tipped to Feature New Glass Design That Might Reduce Display Crease
  10. Samsung Galaxy Z Fold 8 Listing on Chinese Certification Database Seemingly Confirms Charging Upgrade
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.