Xiaomi Technology A.I CyberSecurity Scoring
Xiaomi Technology
Company Information
Website:http://www.mi.com/global
Employees number:23,777
Number of followers:1,542,205
NAICS:5112
Industry Type:Software Development
Homepage:mi.com
Xiaomi Technology Risk Score (AI oriented)
Between 800 and 849
Xiaomi TechnologySoftware Development
Updated:
20/05/2026
20/05/2026
812/1000
Good
A
Xiaomi Technology Global Score (TPRM)
xxxx
Xiaomi TechnologySoftware Development
Score locked

Xiaomi TechnologyGood
Current Score
812A (GOOD)
01000
3 incidents
-7 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
809
MAY 2026
811
APRIL 2026
811
MARCH 2026
824
Cyber Attack
28 Feb 2026 • Xiaomi Technology
Xiaomi, Google and Oppo: Oblivion malware quietly hijacks your Android device while bypassing top security, letting anyone control phones with little effort
New Android RAT 'Oblivion' Bypasses Security Protections, Grants Full Device Control
812
CRITICAL-12
OPPXIAAND1772310272
New Android RAT "Oblivion" Bypasses Security Protections, Grants Full Device Control
Security researchers at Certo have identified Oblivion, a sophisticated Android Remote Access Trojan (RAT) targeting devices running Android 8 through 16. Sold on a subscription basis starting at $300, the malware is designed to evade detection and grant attackers persistent control over infected devices.
Oblivion is marketed as compatible with heavily customized Android systems from manufacturers like Samsung, Xiaomi, and Oppo. Its package includes a builder tool, allowing buyers to generate malicious apps with custom names and icons, alongside a dropper that mimics legitimate update prompts. Infection typically occurs when users install apps from unofficial sources, though the malware’s polished interface suggests careful refinement to enhance credibility.
A key feature of Oblivion is its abuse of Android’s Accessibility Service a feature intended to assist users with disabilities to bypass manual permission approvals. Once active, the malware can silently intercept SMS messages, two-factor authentication (2FA) codes, and push notifications, while also logging keystrokes in real time. Attackers gain remote control capabilities, including the ability to launch or remove apps, unlock devices using stolen credentials, and interact with the device through concealed sessions, all while displaying fake overlays to deceive the user.
The malware employs anti-removal mechanisms to block attempts to revoke permissions or uninstall it, and its icon suppression further conceals its presence. Despite Google’s efforts to restrict Accessibility Service abuse, Oblivion reportedly bypasses protections even on the latest Android versions, highlighting persistent gaps in platform-level defenses.
Unlike traditional malware relying on technical exploits, Oblivion’s effectiveness stems from social engineering and automation. Its subscription-based model lowers the barrier for attackers, enabling even those with minimal expertise to gain control over devices, exfiltrate sensitive data, and manipulate apps remotely. The emergence of such tools underscores the growing threat posed by commercially available malware and the challenges in detecting evolving attack methods.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
824
JANUARY 2026
824
DECEMBER 2025
824
NOVEMBER 2025
823
OCTOBER 2025
823
SEPTEMBER 2025
823
AUGUST 2025
823
JULY 2025
823
JUNE 2025
825
Vulnerability
16 Jun 2025 • Xiaomi Technology
Xiaomi: Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes
Critical Bluetooth Vulnerabilities Expose Xiaomi Redmi Buds to Data Leaks and DoS Attacks
823
CRITICAL-2
XIA1768816067
Critical Bluetooth Vulnerabilities Expose Xiaomi Redmi Buds to Data Leaks and DoS Attacks
Security researchers have identified two severe vulnerabilities in the firmware of Xiaomi’s Redmi Buds series, affecting models from the Redmi Buds 3 Pro to the Redmi Buds 6 Pro. The flaws, rooted in the devices’ Bluetooth implementation, enable attackers to extract sensitive data or force disconnections all without requiring pairing or user interaction.
The first vulnerability, CVE-2025-13834, is an information leak caused by improper bounds checking in the RFCOMM protocol. When exploited with a malformed TEST command, the firmware reads from uninitialized memory, returning up to 127 bytes of data, including phone numbers from active calls. The flaw mirrors the infamous Heartbleed bug, allowing repeated, undetected data extraction.
The second, CVE-2025-13328, is a Denial of Service (DoS) attack triggered by flooding the device with legitimate TEST or Modem Status Command frames. This overwhelms the firmware, causing a crash that disconnects the earbuds from the paired device. Recovery requires physically resetting the earbuds in their charging case.
Exploitation is alarmingly simple: Attackers only need the MAC address of the target earbuds, obtainable via standard Bluetooth sniffing tools. Tests confirmed attacks can be executed from up to 20 meters away, though physical barriers may reduce range. No authentication or user interaction is required, making the vulnerabilities particularly dangerous in public spaces where Bluetooth sniffing is feasible.
As of disclosure, Xiaomi has not released a firmware patch to address the flaws. The vulnerabilities were discovered by researchers Choongin Lee, Jiwoong Ryu, and Heejo Lee, with no official remediation timeline provided. Until fixes are deployed, users remain exposed to privacy breaches and persistent disruptions.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2024
825
Vulnerability
16 Jun 2024 • Xiaomi Technology
Xiaomi
Xiaomi Interconnection Application Authentication Bypass Vulnerability
824
CRITICAL-1
XIA605062425
A severe security vulnerability has been discovered in Xiaomi’s interoperability application, potentially exposing millions of users to unauthorized device access. The vulnerability, assigned CVE-2024-45347, carries a severe CVSS score of 9.6. Attackers can exploit this vulnerability to bypass authentication mechanisms and gain complete unauthorized access to victim devices running the affected software. This could result in the compromise of sensitive data, installation of malicious software, or persistent access to the compromised device.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Xiaomi Technology ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in May 2026 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in April 2026 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in March 2026 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in February 2026 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in January 2026 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in December 2025 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in November 2025 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in October 2025 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in September 2025 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in August 2025 ??
What was Xiaomi Technology's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Xiaomi Technology's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Xiaomi Technology ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Xiaomi Technology's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?