Millions of Xiaomi phones at risk of remotely installed malware
A portion of the 70 million phones shipped by Xiaomi last year are affected by the vulnerability.

By Zack Whittaker for Zero Day | July 11, 2016 -- 14:18 GMT (07:18 PDT) | Topic: Security
Millions of Xiaomi phones are vulnerable to a flaw that could allow an attacker to remotely install malware.
The vulnerability, now fixed, was found in the analytics package in Xiaomi s custom-built Android-based operating system. Security researchers at IBM, who found the flaw, discovered a number of apps in the package that were vulnerable to a remote code execution flaw through a man-in-the-middle attack -- one of which would allow an attacker to run arbitrary code at the system-level.