Check Point Research recently discovered a vulnerability in a preinstalled app in one of the worlds biggest mobile vendors, Xiaomi. Ironically, it was the pre-installed security app, Guard Provider, which should protect the phone from malware, which exposes the user to an attack. Due to the unsecured nature of the network traffic to and from Guard Provider and the use of multiple SDKs within the same app, a threat actor could connect to the same Wi-Fi network as the victim and carry out a Man-in-the-Middle attack.”]
Source: https://blog.checkpoint.com/2019/04/04/xiaomi-vulnerability-when-security-is-not-what-it-seems/

