Thursday, April 25, 2024
News

Xiaomi fixes bugs in its mobile payment mechanism

   SocialTwist Tell-a-Friend    Print this Page   COMMENT

New Delhi | Saturday, 2022 1:15:12 AM IST
Global smartphone player Xiaomi has fixed some bugs that were identified in its mobile payment mechanism by cyber security researchers, Check Point Research (CPR) said on Friday.

Left unpatched, an attacker could steal private keys used to sign Wechat Pay control and payment packages, and an unprivileged Android app could have created and signed a fake payment package.

The cyber-security researchers disclosed its findings to Xiaomi, which acknowledged and issued immediate fixes for the bugs.

"We discovered a set of vulnerabilities that could allow forging of payment packages or disabling the payment system directly, from an unprivileged Android application," said Slava Makkaveev, security researcher at Check Point.

Over 1 billion users could have been affected by the bugs, if left unpatched.

"We were able to hack into WeChat Pay and implemented a fully worked proof of concept. Our study marks the first time Xiaomi's trusted applications are being reviewed for security issues," Makkaveev added.

The cyber-security company immediately disclosed the findings to Xiaomi, which "worked swiftly to issue a fix".

The devices studied by CPR were powered by MediaTek chips.

The team detailed two ways to attack the trusted code.

"First, from an unprivileged Android app, where the user installs a malicious application and launches it. The app extracts the keys and sends a fake payment packet to steal the money," said the CPR team.

Second, if the attacker has the target devices in their hands.

"The attacker roots the device, then downgrades the trust environment, and then runs the code to create a fake payment package without an application," it added.

--IANS na/

( 276 Words)

2022-08-12-19:08:03 (IANS)

 
  LATEST COMMENTS (0)
POST YOUR COMMENT
Comments Not Available
 
POST YOUR COMMENT
 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
 
MORE SCIENCE NEWS
Study reveals positive effect of midazol...
Study finds how liver inflammation assoc...
Study reveals novel therapeutic target f...
Study finds common complication of atria...
Researchers discover how complexities in...
Study finds how adding chemotherapy to h...
More...
 
INDIA WORLD ASIA
Congress hates India's constitution, its...
Indira Gandhi, Sonia Gandhi all took hus...
'She cried for terrorists': Nadda hits o...
Madhya Pradesh: PM Modi recalls old days...
Delhi: Ice cream vendor stabbed to death...
BJP files complaint to ECI against Congr...
More...    
 
 Top Stories
"Has strong ability to read game": ... 
TMC lodges complaint with ECI again... 
Neha Hiremath murder case: NSUI wor... 
Madhya Pradesh: Girls outshine boys... 
Pak player Sana Mir named ambassado... 
Appointment of CPS: Next hearing in... 
"It is a matter of pride for us": H... 
US State Dept official visits Jain ...