Critical Vulnerability in Xiaomi’s Interoperability App Exposes Users to Unauthorized Access

A serious security vulnerability, identified as CVE-2024-45347, has been found in Xiaomi’s interoperability application, potentially putting millions of users at risk. With a high CVSS score of 9.6, this flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to devices running the affected software.


The vulnerability arises from a critical flaw in the app’s verification logic, enabling malicious actors to circumvent normal security checks. This could lead to complete system compromise, allowing attackers to access sensitive data, install malware, or maintain persistent access to compromised devices.
Discovered by Liu Xiaofeng from Shandong University, the vulnerability affects Xiaomi’s Interconnection Application version 3.1.895.10. Users are urged to update to the patched version 3.1.921.10 immediately to mitigate risks.


While Xiaomi has not confirmed any active exploitation of this vulnerability, the severity of the flaw necessitates prompt action. The interoperability application is vital for seamless connectivity between Xiaomi devices and smart home products, highlighting the importance of security in the company’s ecosystem.
Xiaomi encourages security researchers to participate in their bug bounty program through MiSRC, reinforcing their commitment to user safety and proactive vulnerability management.
- Other (43)
- Ransomware (153)
- Events and News (27)
- Features (45)
- Security (484)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (50)
- Malware Alerts (230)
- Cyber Attack (295)
- Data Backup (13)
- Data Breach (125)
- Phishing (164)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (70)
- Android Security (76)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (71)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (24)
- Uber (1)
- YouTube (1)
- Trojan (4)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (37)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (25)