Xiaomi Could Be Sending Your Browser Data to China, Even in 'Incognito' Mode: Report

Xiaomi is said to have a system that transports user data to remote servers hosted by Web domains registered in Beijing.

Advertisement
By Jagmeet Singh | Updated: 2 May 2020 09:20 IST
Highlights
  • Xiaomi is allegedly send browsing data even when using “incognito” mode
  • The company is also reportedly recording user patterns and behaviour
  • Xiaomi has a history of having security and privacy concerns

Xiaomi is currently the leading smartphone maker in India

Xiaomi once again faces allegations that it is silently sending user data to remote servers. Security researchers claim that the Chinese company, which leads the smartphone market in India and is amongst the top-five smartphone makers globally, has provided loopholes on its phones to transmit data to remote servers hosted by Alibaba. Amongst other preloaded apps, the default Web browser on Xiaomi's Redmi and Mi series phones were found recording Web history of users even when switched to “incognito” mode. Xiaomi has denied the claims, and added that while it tracks some anonymous browsing data, it does not share this with third-parties.

Security researchers Gabi Cirlig and Andrew Tierney were able to spot various backdoors in Xiaomi phones that help the company obtain user data, without getting any consent from its users, reported Forbes. Cirlig discovered that his Redmi Note 8 was “watching much of what he was doing on his phone” and was sending all that data to remote servers hosted by Alibaba.

The researcher said that his identity and his private life were being exposed through the loopholes that Xiaomi seems to have intentionally added to the software available on the Redmi phone. Further, he was able to find that the company was recording details even when he was browsing the Web on his phone using the incognito mode. In addition to the browsing data, Cirlig's Redmi Note 8 was allegedly recording what folders he opened and which screens he swiped. This includes the status bar and the settings page. All that data is said to have been transported to remote servers located in Singapore and Russia, hosted by the Web domains registered in Beijing, where Xiaomi has its headquarters.

Advertisement

Issues aren't limited to a particular model
Cirlig found that the security flaws weren't limited to his Redmi Note 8 and according to him, exist across various Xiaomi phones. He was able to confirm their existence by downloading the firmware for the Mi 10, Redmi K20, and Mi Mix 3. Like Cirlig, Tierney also found Xiaomi's that browsers available for down on Google Play — Mi Browser Pro and Mi Browser — were collecting the same user data. Both browsers have over 15 million downloads, as per the stats on Google Play.

Advertisement

Xiaomi appears to use the data it acquires from users to understand their behaviour. The company has already partnered with behavioural analytics startup Sensors Analytics that could help understand how people are using smartphones. Both Cirlig and Tierney found Xiaomi apps were sending user data to domains that apparently have references to Sensor Analytics.

Xiaomi has denied the issues raised by the security researcher. Responding to Forbes, Xiaomi said, “The research claims are untrue.” It also stated that privacy and security are of “top concern.” Further, the company said that it doesn't collect information in the incognito mode, though it did mention that it records “anonymous browsing data” to improve the user experience. A Xiaomi spokesperson also confirmed to Forbes the relationship with Sensor Analytics for using a data analysis solution to collect “anonymous data stored on Xiaomi's own servers.” However, the company claims that the data isn't shared with the startup or any other third parties.

Advertisement

Repeated attempts
This isn't the first time when Xiaomi was found to have backdoors to acquire user data without explicit permission. The company has faced many allegations of sending users' personal information back to its servers. Some security concerns were even raised by authorities such the Indian Air Force back in 2014. It did offer some updates to its software to address some of those concerns and resolve some serious issues.

Nevertheless, the security issues reported in the past haven't impacted Xiaomi's business and market presence. The company is currently the number one smartphone maker in India with a strong 30 percent market share, as per a recent report by Counterpoint Research. It also comes under the top-five smartphone makers globally.

Update — Xiaomi has since released the following comment: 

Advertisement

“Xiaomi was disappointed to read the recent article from Forbes. We feel they have misunderstood what we communicated regarding our data privacy principles and policy. Our user's privacy and internet security is of top priority at Xiaomi; we are confident that we strictly follow and are fully compliant with local laws and regulations. We have reached out to Forbes to offer clarity on this unfortunate misinterpretation.”


Will OnePlus 8 series be able to take on iPhone SE (2020), Samsung Galaxy S20 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Xiaomi, MIUI
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Launched With Snapdragon 8 Elite Gen 5 SoC at This Price
  2. iQOO 15 Confirmed to Launch in India on This Date
  3. Wobble Will Launch Its First Smartphone in India on This Date
  4. Oppo Find X9 Series Launching Today: All You Need to Know
  5. Battlefield 6's Free-to-Play Battle Royale Mode Launches October 28
  6. iPhone 17 Review
  7. Moto X70 Air Launch Teased for India: Price, Specifications Expected
  8. Xiaomi 17 Ultra Might Launch With These Cameras
  9. Samsung Showcases Its Upcoming Galaxy Z TriFold Ahead of Launch
  10. Apple's iPhone 20 to Feature Solid-State Buttons in 2027, Tipster Claims
  1. OpenAI Explains How It Assesses Mental Health Concerns of ChatGPT Users, Sparks Backlash
  2. Oppo Find X9 Series India Launch Teased Hours Ahead of Global Debut; Exchange Offers, Other Benefits Revealed
  3. iQOO Neo 11 Confirmed to Launch With Snapdragon 8 Elite SoC, 8K VC Cooling Solution
  4. Wobble Announces Launch Date for First Smartphone in India: Expected Specifications, Features
  5. Lava Teases Upcoming Smartphone Launch in India; Lava Agni 4 Likely to Make Its Debut Soon
  6. Apple's iPhone 20 to Feature All Solid-State Haptic Buttons in 2027, Tipster Claims
  7. Samsung Galaxy Z Fold 8 Said to Feature Larger Battery, Reintroduce S-Pen Support
  8. Battlefield Redsec, Battlefield 6's Free-to-Play Battle Royale Mode, Arrives October 28
  9. Bitcoin Slips Below $114,000 as Traders Remain Cautious Amidst Market Uncertainty
  10. Samsung Galaxy Z TriFold Officially Showcased at APEC Summit Ahead of Launch: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.