Xiaomi Responds to eScan Claims That MIUI Is Riddled With Security Flaws

Advertisement
By Gadgets 360 Staff | Updated: 10 August 2017 19:33 IST
Highlights
  • eScan in a 36-page report claims MIUI is not secure
  • It points to system app flaws affecting user data security
  • Xiaomi has responded to the eScan report in a statement

Security solutions company eScan on Thursday in a 36-page report alleged that Xiaomi's MIUI custom Android ROM has multiple flaws that affected the security of user data. Xiaomi system apps such as the uninstall mechanism and Mi Mover were some of the flawed aspects of MIUI, the report stated. The Chinese smartphone company has refuted the allegations however, in a statement to Gadgets 360.

A Xiaomi spokesperson in an emailed statement told Gadgets 360 that all of eScan's data security concerns are valid only if a perpetrator gains physical access to an unlocked smartphone. Such a scenario already places user data at great risk, and Xiaomi also pointed to the addition of login layers that have been introduced in the user data migration app Mi Mover, as well as its recommendations for users to utilise a lockscreen security feature such as PINs, pattern locks, and the fingerprint sensor.

Advertisement

In its report, eScan claims "Xiaomi's system apps have unknowingly introduced multiple flaws into the functional working of most of the apps. The functional aspects of Anti-Theft security apps and Android for Work apps are affected by the uninstall procedure implemented by Xiaomi. Furthermore, the MI-Mover app which assists in user data migration also poses significant threats to the installed apps. Although, Xiaomi alone cannot be held responsible; the app developers are also equally responsible for not taking into consideration that there existed a huge possibility of their application's app-system-data getting cloned/ copied. This particular use-case existed since the day devices started getting rooted and app-system-storage was compromised. It's surprising that app developers never realized that the data which they are storing on app-system-storage is vulnerable on rooted phones. Although Xiaomi's MI Mover allows the users to copy all their data, it goes one step ahead and copies from the app-system-storage areas too."

The eScan report claims that the "uninstallation procedure implemented by Security Apps is adversely affected on Xiaomi Devices," and "apps based on the guidelines provided for implementing Android for Works are affected by the improper implementation of uninstallation procedure implemented on Xiaomi devices."

Advertisement

eScan admits that physical access of an unlocked device is required for its concerns to apply, but then asks what precautions do Xiaomi device users have to take into consideration when handing their devices over to service centre employees, and with anti-theft security mechanisms affected, questions how Xiaomi users would ensure their device doesn't get stolen.

You can read the Xiaomi spokesperson's full statement below.

Advertisement

At Xiaomi, user privacy is of utmost importance.

Escan earlier today shared a report which list downs few concerns in MIUI. We strongly disagree with the allegations made by Escan in their report. As a global Internet company, Xiaomi takes all possible steps to ensure our devices and services adhere to our privacy policy.

Advertisement

Any perpetrator who gains physical access to an unlocked phone, is capable of malicious activity and an unlocked phone is greatly at risk of user data being stolen.

This is why, we at Xiaomi encourage our users to be more aware of guarding their private data using PIN, Pattern locks, or the onboard fingerprint sensor available on most of our smartphones. In fact, prompting users to enable fingerprint lock is a standard step when setting up a Xiaomi smartphone for first use.

Mi Mover is designed to be a convenient tool for our users to move their data from an old smartphone to a new phone. In order for Mi Mover to initiate this process, a password is required.

More importantly, in order to use Mi Mover, the smartphone has to be unlocked.

Thus, there are two layers of protection for the user – phone lock and a Mi Mover password that are necessary.

Further, as per the Escan report, "As part of exploiting the issue you describe, someone needs to take control of a user's mobile phone and get that phone in an unlocked state. This is a very high barrier to entry and seems unlikely to happen commonly, making this more of a theoretical attack. The protection, in this case, is to not allow someone to steal and unlock your phone.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Pro+ With 6,500mAh Battery Debuts in India at This Price
  2. Xiaomi 17T Launches in India With Leica-Tuned Triple Rear Cameras
  3. Triple Solar Flare Eruption Sparks G3 Geomagnetic Storm Watch for Earth
  4. Motorola Edge 70 Pro+ vs Vivo V70 vs Nothing Phone 4a Pro Compared
  5. Xiaomi 17T First Impressions
  6. Amazfit Balance 3, Balance Ultra Launched With Hyrox Tools, Up to 30-Day Battery Life
  7. OnePlus 16, iQOO 16 Could Launch Earlier Than Expected, Tipster Claims
  8. Xiaomi TV FX Mini LED Series With Up to 75-Inch Screen Launched in India
  9. iPhone 18 Pro Max Leak Suggests It Has the Same Thickness as This iPhone
  1. Sun Unleashes Triple Solar Flare Blast, Triggering G3 Geomagnetic Storm Alert
  2. Tomb Raider: Legacy of Atlantis Gets AI Disclosure on Steam, Crystal Dynamics Clarifies AI Use
  3. iPhone 18 Pro Max Leak Hints at No Significant Changes to Smartphone's Thickness Over Predecessor
  4. OnePlus 16 and iQOO 16 Development Progressing 'Rapidly', Could Launch Sooner Than Expected, Tipster Claims
  5. Nintendo Switch 2 Could Get a Removable Battery Variant Next Year to Comply With EU Regulations
  6. Maa Behen Out on OTT: Know Where to Stream This Madhuri Dixit Starrer Film
  7. FIFA World Cup 2026: LASD Issues Warning Over Crypto Scams Days Ahead of World Cup
  8. Night Shift For Cuties Now Available for Streaming Online: What You Need to Know
  9. Dridam OTT Release Date: When and Where to Watch Shane Nigam’s Crime Thriller Online
  10. Gram Chikitsalay Season 2 OTT Release Date: When and Where to Watch it Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.