cxo voice
  • Business
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • Press Release
    • Submit Press Release
No Result
View All Result
  • Business
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • Press Release
    • Submit Press Release
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home News Cyber Security

Xiaomi Fixes the Security Flaws In Its Mobile Payment Mechanism

News Desk by News Desk
August 13, 2022
A A
Security flaws Xiaomi

Check Point Research (CPR) recognized the security flaws in Xiaomi’s mobile payment mechanism. The vulnerabilities were in Xiaomi’s Trusted Environment, which is reliable for storing and processing sensitive data such as keys and passwords. CPR responsibly revealed its findings to Xiaomi, which acknowledged and fixed the security flaws. 

Over 1 billion users could have been affected, an attacker could steal private keys used to sign Wechat Pay control and payment packages. In the most ominous case, an unprivileged Android app could have created and signed a fake payment package. The devices studied by CPR were powered by MediaTek chips. 

CPR main findings

Entrusted apps on Xiaomi phone can be downgraded

Xiaomi can embed and sign their own entrusted applications. CPR findings show that an attacker can reposition an old version of a trusted app to the device and use it to overwrite the new app file. Therefore, an attacker can bypass security fixes made by Xiaomi or MediaTek in trusted apps by downgrading them to unpatched versions. CPR found several vulnerabilities in the thhadmin trusted app, which is responsible for security management that could be exploited to leak stored keys or to execute code in the context of the app and then practically perform malicious forged actions.

Embedded mobile payment framework compromised.

Xiaomi devices have an embedded mobile payment framework named Tencent Soter that provides an API for third-party Android applications to integrate the payment capabilities. Its primary function is to provide the ability to verify payment packages transferred between a mobile application and a remote backend server which are essentially the security and safety we all count on when we perform mobile payments.

According to Tencent, hundreds of millions of Android devices support Tencent soter.

The security flaws CPR found, which Xiaomi assigned CVE-2020-14125, ultimately compromised the Tencent soter platform, allowing an unauthorized user to sign fake payment packages.

ADVERTISEMENT

Two Attack Paths

CPR discovered two ways to attack the trusted code: 

1. From an unprivileged Android app: The user installs a malicious application and launches it. The app extracts the keys and sends a fake payment packet to steal the money.

2. If the attacker has the target devices in their hands: The attacker rootes the device, then downgrades the trust environment and then runs the code to create a fake payment package without an application.

Slava Makkaveev, Security Researcher at Check Point, said, “We discovered a set of vulnerabilities that could allow forging of payment packages or disabling the payment system directly from an unprivileged Android application. We were able to hack into WeChat Pay and implemented a fully worked proof of concept. Our study marks the first time Xiaomi’s trusted applications are being reviewed for security issues. We immediately disclosed our findings to Xiaomi, who worked swiftly to issue a fix. Our message to the public is to constantly make sure your phones are updated to the latest version provided by the manufacturer. If even mobile payments are not secure, then what is?”

Also Read: Remote Work Needs a Redesigned Enterprise Network to Strengthen Cybersecurity

News Desk

News Desk

by CXO VOICE team memebrs, [email protected]

Related Posts

Check Point Quantum Firewall
Cyber Security

Check Point Launches Quantum Firewall Software R82.10 to Secure the AI-Driven Enterprise

December 5, 2025
Electric Vehicles on the Road
EV

Gartner Forecasts 116 Million Electric Vehicles on the Road by 2026, Signalling a Pivotal Shift in Global Mobility

December 5, 2025
ABB invests in OctaiPipe to partner in AI-optimized energy efficiency for data centre cooling
Business

ABB invests in OctaiPipe to partner in AI-optimized energy efficiency for data centre cooling

December 4, 2025
India Cyber Threat Report
News

India Records 265 Million Cyber Attacks; Seqrite Releases the India Cyber Threat Report 2026

December 4, 2025
AI in Manufacturing
AI

AI Set to Reshape Manufacturing Profitability, Insights from TCS Study

December 4, 2025
Ericsson Partners with LotusFlare
Business

Ericsson Partners with LotusFlare to Boost adoption of network APIs

December 3, 2025
Avathon and Google
Business

Avathon and Google Cloud Unveil Autonomous Intelligence Platform for Energy Operations

December 3, 2025
ING Broadcom
Business

ING Partners with Broadcom to Modernize Private Cloud Infrastructure with VMware Cloud Foundation 9.0

December 3, 2025
Load More
ADVERTISEMENT

Latest Updates

Check Point Quantum Firewall

Check Point Launches Quantum Firewall Software R82.10 to Secure the AI-Driven Enterprise

by Deepa Sharma
2 days ago

Electric Vehicles on the Road

Gartner Forecasts 116 Million Electric Vehicles on the Road by 2026, Signalling a Pivotal Shift in Global Mobility

by News Desk
2 days ago

ABB invests in OctaiPipe to partner in AI-optimized energy efficiency for data centre cooling

ABB invests in OctaiPipe to partner in AI-optimized energy efficiency for data centre cooling

by News Desk
3 days ago

India Cyber Threat Report

India Records 265 Million Cyber Attacks; Seqrite Releases the India Cyber Threat Report 2026

by Deepa Sharma
3 days ago

AI in Manufacturing

AI Set to Reshape Manufacturing Profitability, Insights from TCS Study

by Deepa Sharma
3 days ago

Ericsson Partners with LotusFlare

Ericsson Partners with LotusFlare to Boost adoption of network APIs

by Deepa Sharma
4 days ago

Expert Views

India's Cybersecurity ecosystem
Cyber Security

Inside India’s $20 Billion Cybersecurity Ecosystem: Growth, Challenges, and the Road Ahead

November 11, 2025
From Coaches to Control Rooms: 5 Trends Shaping Railway Smart Video Storage
Opinion

From Coaches to Control Rooms: 5 Trends Shaping Railway Smart Video Storage

November 8, 2025
AI Underwriter
AI

Why AI is the Underwriter’s Strongest Ally

October 30, 2025
agentic AI threats
Cyber Security

Top 10 agentic AI threats, and how to defend against them

October 17, 2025
Your Face, Your Data: The Hidden Risks of Uploading to AI Tools
Cyber Security

Your Face, Your Data: The Hidden Risks of Uploading to AI Tools

October 7, 2025

Get Latest Update

Subscribe to our mailing list to receives newsletter direct to your inbox!

ADVERTISEMENT

Leaders Interviews

NewgenONE
Interview

Reimagining Enterprise Transformation: Varun Goswami on the Future of NewgenONE and AI-Driven Automation

-
Jagat Shah, Chairman & CEO of MITSUMI Group
Leaders Talk

Leadership in Emerging Markets: Exclusive Interview with Jagat Shah, Chairman & CEO of MITSUMI Distribution

-
Tokenization
Interview

Revolutionizing Finance: An Exclusive Interview with Sid Ugrankar, Co-founder of Qila.io on the Future of Blockchain and Tokenization

-
Steve Wilson, GenAI Cybersecurity LLMs
Cyber Security

How effective is GenAI in cybersecurity? The role of LLMs and AI in security solutions. [Interview with Steve Wilson]

-

Entrepreneur

Persistent Gender Bias Clouds Perceptions of Leadership in Tech: Study Finds

Top Leadership Skills Entrepreneurs Need in the Age of AI

Samsung Electronics appoints its first female president

Inspiring Women Entrepreneurs in India (2022)

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. Our coverage spans key sectors, including IT, technology, banking, finance, cybersecurity, engineering, and automobiles.

Connect with us

Easy Links

  • Cryptocurrency
  • Event
  • Blockchain
  • Press Release
  • Resources & Downloads

Write Us

[email protected]
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Feedback

Copyright © 2025 CXOVoice - All Right Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • News
  • Business
  • Technology
  • Cyber Security
  • Opinion
  • Leaders Talk

Copyright © 2025 CXOVoice - All Right Reserved