Check Point Research: More on the attacks on Xiaomi devices

After our post yesterday Attention: vulnerabilities in Xiaomi phones, Check Point Research sent us a press release describing the attack:

Check Point Research (CPR) identified vulnerabilities in the mobile payment mechanism . If this is not fixed, an attacker could steal the codes used to sign Wechat Pay checks and payments.

In the worst case scenario, an unauthorized Android app could create and sign a fake payment package.

Xiaomi logo

Check Point Research (CPR) has identified vulnerabilities in the Xiaomi mobile payment engine. If not fixed, an attacker could steal the private keys used to sign Wechat Pay's control and payment packets. In the worst case, an unauthorized Android app could create and sign a fake payment package.

In particular, vulnerabilities were found in Xiaomi's trusted environment, which is responsible for storing and managing sensitive information such as passwords. The devices studied by CPR were powered by its chips .

Two types of attack

CPR discovered two ways to attack trusted code:

  1. From an unauthorized Android app: O installs a malicious application and launches it. The app extracts the keys and sends a fake payment packet to steal the money
  2. If the attacker has the target devices in his hands: The attacker roots the device, then degrades the trust environment, and then executes the code to create a fake payment package without an application.

CPR responsibly disclosed its findings to Xiaomi. Xiaomi has acknowledged and issued fixes.

Slava Makkaveev, Security Researcher, Check Point commented:

"Ανακαλύψαμε ένα σύνολο ευπαθειών που θα μπορούσαν να επιτρέψουν την παραποίηση πακέτων πληρωμών ή την απενεργοποίηση του συστήματος πληρωμών απευθείας, από μια εφαρμογή Android. Καταφέραμε να παραβιάσουμε το WeChat Pay και να υλοποιήσουμε μια πλήρως ολοκληρωμένη επίδειξη της παραβίασης."

"Η μελέτη μας σηματοδοτεί την πρώτη φορά που οι αξιόπιστες εφαρμογές της Xiaomi εξετάζονται για θέματα ασφαλείας. Κοινοποιήσαμε αμέσως τα ευρήματά μας στην Xiaomi, η οποία εργάστηκε γρήγορα για να εκδώσει μια διόρθωση. Το μήνυμά μας προς το κοινό είναι να βεβαιώνεστε συνεχώς ότι τα τηλέφωνά σας είναι ενημερωμένα στην τελευταία έκδοση που παρέχεται από τον κατασκευαστή. Αν ακόμη και οι πληρωμές μέσω κινητού δεν είναι ασφαλείς, τότε τι είναι;"

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
xiaomi, Check Point Research, iguru

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).