Platform
android
Component
xiaomi-mi-connect-service
Fixed in
3.1.896
CVE-2024-45347 describes an unauthorized access vulnerability discovered in the Xiaomi Mi Connect Service application. This flaw allows attackers to bypass validation checks and potentially gain access to a victim's device without proper authorization. The vulnerability impacts versions 3.1.895.10–3.1.895.10 of the application, and a fix is available in version 3.1.896.
The impact of CVE-2024-45347 is significant due to the potential for unauthorized device access. An attacker exploiting this vulnerability could potentially access sensitive data stored on the device, including personal information, contacts, and potentially control connected smart home devices managed through the Mi Connect Service. The scope of access would depend on the permissions granted to the Mi Connect Service application on the victim's device. Successful exploitation could lead to privacy breaches, data theft, and potentially even device compromise.
CVE-2024-45347 was published on 2025-06-23. The vulnerability's CRITICAL CVSS score indicates a high probability of exploitation. Public proof-of-concept (POC) code is currently unavailable, but the severity suggests that attackers may actively seek to exploit this vulnerability. Monitor security advisories and threat intelligence feeds for any indications of active exploitation campaigns.
Exploit Status
EPSS
0.05% (17% percentile)
CISA SSVC
CVSS Vector
The primary mitigation for CVE-2024-45347 is to immediately upgrade the Xiaomi Mi Connect Service application to version 3.1.896 or later. Users should ensure automatic updates are enabled to receive the fix promptly. As a temporary workaround, users can restrict the permissions granted to the Mi Connect Service application to minimize the potential impact of a successful attack. Regularly review app permissions and revoke any unnecessary access.
Update the Mi Connect Service APP to the latest version available in the app store. This will resolve the unauthorized access vulnerability. Refer to the Xiaomi security bulletin for more details.
Vulnerability analysis and critical alerts directly to your inbox.
CVE-2024-45347 is a CRITICAL vulnerability in Xiaomi Mi Connect Service allowing unauthorized access due to flawed validation logic. It affects versions 3.1.895.10–3.1.895.10.
You are affected if you are using Xiaomi Mi Connect Service version 3.1.895.10–3.1.895.10 and have not upgraded.
Upgrade Xiaomi Mi Connect Service to version 3.1.896 or later. Enable automatic updates to ensure you receive the fix promptly.
While no public exploits are currently available, the CRITICAL severity suggests a high likelihood of active exploitation.
Refer to the official Xiaomi security advisory for details and updates regarding CVE-2024-45347.
Upload your dependency file and we'll tell you instantly if this and other CVEs hit you.
Upload your build.gradle file and we'll tell you instantly if you're affected.