Check Point has reported a vulnerability in the Guard Provider application for Xiaomi smartphones. This flaw allows malicious code to be installed on devices without the owner's awareness. Ironically, the program was supposed to protect smartphones from dangerous applications.

It is reported that the vulnerability enables a MITM (Man-in-the-Middle) attack. This occurs if the attacker is on the same Wi-Fi network as the victim. The attack will grant access to all data transmitted by any given application. It also allows for adding code to steal data, monitor, or extort. A cryptocurrency miner could also be useful.
The Chinese corporation has already responded and released a patch to fix the vulnerability. However, Check Point specialists believe that some smartphones are already infected. In fact, over 4 million Xiaomi smartphones were sold in Russia in 2018, and the flaw was not discovered immediately.
Moreover, Alexey Malnev, head of the incident monitoring and response center at Infosystems Jet, noted that the situation with Xiaomi is not unique. Such dangers exist for all smartphones and tablets.
"The greatest risk of such vulnerabilities lies in their widespread nature due to the popularity of mobile devices themselves. This enables both large-scale attacks to form botnet networks for subsequent malicious use, as well as targeted attacks aimed at stealing information and funds from mobile clients or penetrating corporate information systems," explained the specialist.
And the head of the technical support department for products and services at ESET Russia, Sergey Kuznetsov, pointed out that the primary danger lies in public and community Wi-Fi networks, as this is where the attacker and the victim will be on the same segment.
Source: 3dnews.ru
