Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Xiaomi Technology

Xiaomi Technology Vendor Cyber Rating & Cyber Score

mi.com

Xiaomi Corporation was founded in April 2010 and listed on the Main Board of the Hong Kong Stock Exchange on July 9, 2018 (1810.HK). Xiaomi is a consumer electronics and smart manufacturing company with smartphones and smart hardware connected by an IoT platform at its core. Embracing our vision of “Make friends with users and be the coolest company in the users’ hearts”, Xiaomi continuously pursues innovations, high-quality user experience and operational efficiency. The company relentlessly builds amazing products with honest prices to let everyone in the world enjoy a better life through innovative technology. Xiaomi is one of the world's leading smartphone companies. The company has also established the world’s leading consumer


Xiaomi Technology A.I CyberSecurity Scoring

Xiaomi Technology
Company Information
Website:http://www.mi.com/global
Employees number:23,777
Number of followers:1,542,205
NAICS:5112
Industry Type:Software Development
Homepage:mi.com
Xiaomi Technology Risk Score (AI oriented)
Between 800 and 849
logo
Xiaomi TechnologySoftware Development
Updated:
20/05/2026
812/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Xiaomi Technology Global Score (TPRM)
xxxx
logo
Xiaomi TechnologySoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Xiaomi Technology
Xiaomi TechnologyGood
Current Score
812A (GOOD)
01000
3 incidents
-7 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
809Before Incident
MAY 2026
811Before Incident
APRIL 2026
811Before Incident
MARCH 2026
824Before Incident
Cyber Attack
28 Feb 2026Xiaomi Technology
Xiaomi, Google and Oppo: Oblivion malware quietly hijacks your Android device while bypassing top security, letting anyone control phones with little effort

New Android RAT 'Oblivion' Bypasses Security Protections, Grants Full Device Control

812After Incident
CRITICAL-12
OPPXIAAND1772310272
New Android RAT "Oblivion" Bypasses Security Protections, Grants Full Device Control Security researchers at Certo have identified Oblivion, a sophisticated Android Remote Access Trojan (RAT) targeting devices running Android 8 through 16. Sold on a subscription basis starting at $300, the malware is designed to evade detection and grant attackers persistent control over infected devices. Oblivion is marketed as compatible with heavily customized Android systems from manufacturers like Samsung, Xiaomi, and Oppo. Its package includes a builder tool, allowing buyers to generate malicious apps with custom names and icons, alongside a dropper that mimics legitimate update prompts. Infection typically occurs when users install apps from unofficial sources, though the malware’s polished interface suggests careful refinement to enhance credibility. A key feature of Oblivion is its abuse of Android’s Accessibility Service a feature intended to assist users with disabilities to bypass manual permission approvals. Once active, the malware can silently intercept SMS messages, two-factor authentication (2FA) codes, and push notifications, while also logging keystrokes in real time. Attackers gain remote control capabilities, including the ability to launch or remove apps, unlock devices using stolen credentials, and interact with the device through concealed sessions, all while displaying fake overlays to deceive the user. The malware employs anti-removal mechanisms to block attempts to revoke permissions or uninstall it, and its icon suppression further conceals its presence. Despite Google’s efforts to restrict Accessibility Service abuse, Oblivion reportedly bypasses protections even on the latest Android versions, highlighting persistent gaps in platform-level defenses. Unlike traditional malware relying on technical exploits, Oblivion’s effectiveness stems from social engineering and automation. Its subscription-based model lowers the barrier for attackers, enabling even those with minimal expertise to gain control over devices, exfiltrate sensitive data, and manipulate apps remotely. The emergence of such tools underscores the growing threat posed by commercially available malware and the challenges in detecting evolving attack methods.
INCIDENT DETAILS -
TYPE
Malware (Remote Access Trojan - RAT)
MOTIVATION
Financial gain (subscription-based malware sales)Data exfiltrationRemote device control
IMPACT
SMS messagesTwo-factor authentication (2FA) codesPush notificationsKeystrokesDevice credentialsSystems Affected: Android devices (versions 8 through 16)Operational Impact: Persistent remote control of infected devices, ability to launch/remove apps, unlock devices, and manipulate apps remotelyIdentity Theft Risk: High (due to interception of 2FA codes and credentials)
DATA BREACH
SMS messages2FA codesPush notificationsKeystrokesDevice credentialsSensitivity Of Data: High (personally identifiable information, authentication credentials)Data Exfiltration: Yes (remote control enables data exfiltration)Personally Identifiable Information: Yes (credentials, 2FA codes, SMS content)
FEBRUARY 2026
824Before Incident
JANUARY 2026
824Before Incident
DECEMBER 2025
824Before Incident
NOVEMBER 2025
823Before Incident
OCTOBER 2025
823Before Incident
SEPTEMBER 2025
823Before Incident
AUGUST 2025
823Before Incident
JULY 2025
823Before Incident
JUNE 2025
825Before Incident
Vulnerability
16 Jun 2025Xiaomi Technology
Xiaomi: Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes

Critical Bluetooth Vulnerabilities Expose Xiaomi Redmi Buds to Data Leaks and DoS Attacks

823After Incident
CRITICAL-2
XIA1768816067
Critical Bluetooth Vulnerabilities Expose Xiaomi Redmi Buds to Data Leaks and DoS Attacks Security researchers have identified two severe vulnerabilities in the firmware of Xiaomi’s Redmi Buds series, affecting models from the Redmi Buds 3 Pro to the Redmi Buds 6 Pro. The flaws, rooted in the devices’ Bluetooth implementation, enable attackers to extract sensitive data or force disconnections all without requiring pairing or user interaction. The first vulnerability, CVE-2025-13834, is an information leak caused by improper bounds checking in the RFCOMM protocol. When exploited with a malformed TEST command, the firmware reads from uninitialized memory, returning up to 127 bytes of data, including phone numbers from active calls. The flaw mirrors the infamous Heartbleed bug, allowing repeated, undetected data extraction. The second, CVE-2025-13328, is a Denial of Service (DoS) attack triggered by flooding the device with legitimate TEST or Modem Status Command frames. This overwhelms the firmware, causing a crash that disconnects the earbuds from the paired device. Recovery requires physically resetting the earbuds in their charging case. Exploitation is alarmingly simple: Attackers only need the MAC address of the target earbuds, obtainable via standard Bluetooth sniffing tools. Tests confirmed attacks can be executed from up to 20 meters away, though physical barriers may reduce range. No authentication or user interaction is required, making the vulnerabilities particularly dangerous in public spaces where Bluetooth sniffing is feasible. As of disclosure, Xiaomi has not released a firmware patch to address the flaws. The vulnerabilities were discovered by researchers Choongin Lee, Jiwoong Ryu, and Heejo Lee, with no official remediation timeline provided. Until fixes are deployed, users remain exposed to privacy breaches and persistent disruptions.
INCIDENT DETAILS -
TYPE
Information LeakDenial of Service (DoS)
IMPACT
Data Compromised: Phone numbers from active callsSystems Affected: Xiaomi Redmi Buds (models 3 Pro to 6 Pro)Downtime: Disconnection requiring physical resetOperational Impact: Persistent disruptions to device functionalityBrand Reputation Impact: Privacy breaches and disruption risks
DATA BREACH
Type Of Data Compromised: Phone numbersSensitivity Of Data: Personally identifiable information (PII)Data Exfiltration: Yes (via malformed TEST commands)Personally Identifiable Information: Phone numbers
JUNE 2024
825Before Incident
Vulnerability
16 Jun 2024Xiaomi Technology
Xiaomi

Xiaomi Interconnection Application Authentication Bypass Vulnerability

824After Incident
CRITICAL-1
XIA605062425
A severe security vulnerability has been discovered in Xiaomi’s interoperability application, potentially exposing millions of users to unauthorized device access. The vulnerability, assigned CVE-2024-45347, carries a severe CVSS score of 9.6. Attackers can exploit this vulnerability to bypass authentication mechanisms and gain complete unauthorized access to victim devices running the affected software. This could result in the compromise of sensitive data, installation of malicious software, or persistent access to the compromised device.
INCIDENT DETAILS -
TYPE
Authentication Bypass Vulnerability
MOTIVATION
Unauthorized access to victim devices
IMPACT
Data Compromised: Sensitive dataSystems Affected: Xiaomi Interconnection Application 3.1.895.10Operational Impact: Complete system compromise

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Xiaomi Technology ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Xiaomi Technology's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Xiaomi Technology's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Xiaomi Technology ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Xiaomi Technology's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?