MIUI Lock Screen Vulnerability Provided Access to Clipboard Data, Fix Released

Advertisement
By Jagmeet Singh | Updated: 17 April 2019 14:00 IST
Highlights
  • Xiaomi's MIUI allows clipboard data access without unlocking the device
  • The vulnerability exists within the Wallpaper Carousel feature
  • Poco F1 running the latest MIUI is also affected

Xiaomi has released the updated version of Mi Wallpaper Carousel app in Play Store

Xiaomi is already infamous for pushing ads through its MIUI operating system but of late the company's software and apps have also been found to have vulnerabilities. Now, a new flaw has been found in the lock screen implementation of the latest MIUI versions that could give an attacker access to the user's clipboard data. The issue is claimed to be specific to India region and exists not only on Redmi and Mi smartphones but also on the Poco F1. The vulnerability requires physical access to the device to give a backdoor entry to the clipboard data and partial access to user's stored social media credentials. Xiaomi has released an updated version of its Mi Wallpaper Carousel app in the Play Store that has patched the vulnerability.

Security researcher Arif Khan on infosec blog Andmp reports that the latest MIUI stable releases are affected by a vulnerability that could give an attacker ability to access the Xiaomi phone's clipboard. The issue is said to be specific to India region, though it exists on all the recent MIUI builds. The flaw is said to be a part of the Wallpaper Carousel feature that Xiaomi has provided in collaboration with InMobi -- through its Glance app.

The Wallpaper Carousel feature is designed to frequently showcase new wallpapers on the lock screen. Each of the wallpapers presented on the lock screen comes with a title and a Read More button that lets you read the context of the image. The vulnerability primarily exists in the context part of the feature as it lets users share the featured content through their social media accounts without unlocking the device. This also includes the ability to paste data directly from the clipboard. Similarly, users can add data to their clipboard direct from the content being served through the Wallpaper Carousel feature.

Advertisement

While the Wallpaper Carousel feature is disabled by default, anyone who has physical access to the device can enable it directly from the lock screen -- simply by swiping the screen and then tapping the Turn on button.

Advertisement

Xiaomi's Mi Wallpaper Carousel app was found to have a lock screen vulnerability
Photo Credit: Andmp

Advertisement

 

We were able to verify the existence of the flaw on our Poco F1 unit running the latest MIUI 10.3.4.0 version. The researcher claims that he found the vulnerability on a device based on MIUI 10.1.3.0. This suggests that the issue isn't limited to any specific MIUI version and is available not only on some Xiaomi's Redmi and Mi phones but also on the Poco F1 that runs a modified MIUI build.

Advertisement

After the initial media reports about the vulnerability surfaced, Xiaomi has released an updated version of the Mi Wallpaper Carousel app in Google Play, which plugs the vulnerability, restricting access to the clipboard as well as social media accounts. If you use a Xiaomi smartphone, it is recommended that you update the Mi Wallpaper Carousel app on your phone.

We've reached out to Xiaomi for more information on the vulnerability and will update this report when we hear back from the company.

Importantly, this isn't the first time when Xiaomi has hit the headlines over a security flaw in its apps or software. Just earlier this month, the security app Xiaomi Guard Provider, which comes pre-installed on the Xiaomi phones, was discovered with a serious vulnerability that could allow an attacker to wreak havoc by intercepting the traffic linked to the app. The Mi Browser and Mint Browser by the Chinese company were also found to have a critical URL spoofing security issue.

Xiaomi also faces consumer outage over how it serves ads through different MIUI elements. Xiaomi CEO Lei Jun earlier this month revealed that MIUI 11 would restrict ads to some extent and remove vulgar ads.


Do Redmi Note 7 Pro, Redmi Note 7, and Mi Soundbar redefine their price segments? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series 5G Confirmed to Launch in India Soon
  2. Oppo Reno 15 Pro Mini Confirmed to Launch in India Alongside These Models
  3. OnePlus 15R Goes on Sale in India For the First Time Today: Price, Offers
  4. Xiaomi Watch 5, Xiaomi Buds 6 to Launch Alongside Xiaomi 17 Ultra
  5. Here's When the Redmi Pad 2 Pro 5G Will Launch in India
  6. Here's When the Samsung Galaxy S26 Series Could Reach Stores in 2026
  7. Instagram Could Embrace Long-Form Video Content to Compete With TikTok
  8. iQOO Z11 Turbo Design Teased; Specifications Leaked
  9. Oppo Find X9 Ultra Camera Specifications Leaked Ahead of China Launch
  1. OnePlus Phone Codenamed ‘Volkswagen’ With Snapdragon 8s Gen 4 Chip Tipped to Launch in India, Global Markets
  2. How to Keep Your Free Perplexity Pro on Airtel: New Card Requirement Explained
  3. Asus VM670KA AiO All-in-One Desktop PC With 27-Inch Display, Ryzen AI 7 350 Chip Launched in India
  4. A Knight of the Seven Kingdoms OTT Release: Know When and Where to Watch This Prequel of Game of Thrones
  5. Nobody 2 Now Streaming Online: Know Everything About This American Action Thriller Film
  6. Osiris Now Streaming on JioHotstar: Everything You Need to Know
  7. Revolver Rita OTT Release Date Revealed: Know Everything About Streaming, Plot, Cast, and More
  8. ChatGPT Agreeing With Users is Dangerous, Says Lawyer in Murder-Suicide Case: Report
  9. CES 2026: Samsung to Expand Bespoke Appliances With Improved AI Vision, Google Gemini AI
  10. Redmi Pad 2 Pro 5G India Launch Date Announced; Teaser Confirms 12,000mAh Battery
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.