back to article Cafe killer remote code execution affects 140 million MIUI Androids

The most popular stock and third-party Android ROM – used by 170 million people – contains a dangerous since-patched remote code execution hole that could hand attackers total control of handsets. The flaw, found by IBM X-Force researcher David Kaplan (@depletionmode), now of Microsoft, exists in MIUI (pronounced Me, You, I) …

  1. MrWibble

    "A further flaw was found in stock ROM app com.cleanmaster.miui"

    Clean Master? dear god! I'd consider the whole app flawed and destroy if possible.

  2. Anonymous Coward
    Anonymous Coward

    So there is hope of a root exploit for my hudl 2.... stupid tescos locked boot loader... grumbles.

  3. Anonymous Coward
    Anonymous Coward

    MIUI 7.2??

    Then this is quite old news, 7.3 has been out for about a month; still, good to know they are still updating old phones like my HongMi Note 3G, such a pity the new Note drops SD card support; I will have to hold on and hope the next version brings it back.

  4. John 104

    Affected users should upgrade to version 7.2, released as an over-the-air update

    Oh the irony...

    1. Anonymous Coward
      Trollface

      Irony indeed; still, it is faster and safer to update via the MIUI PC Suite after attaching your phone to your Windows PC.

      What? You dont have a Windows PC??

    2. Brian Miller

      CyanogenMod, the most popular strictly third-party ROM, has about 50 million users and supports about 200 devices.

      Affected users should upgrade to version 7.2, released as an over-the-air update.

      But that's for a third-party open source ROM! That's not coming from Xiaomi. If it's left up to the manufacturers, we'll never see a fix for this.

      1. Jeffrey Nonken

        I'm guessing the remark about Cyanogenmod is an aside, just for comparison of usage statistics. I'm wondering if the paragraph was inserted as an afterthought, it is rather confusing. I think Mr. Pauli should move it and add a few more words of context. Or at least add the context, though the following paragraph might want a few more words to properly shift the context back.

  5. jms222

    All I can think is that Android really is a pile of poo.

    1. Jeffrey Nonken

      It has its issues, for certain. But a) I would not want to live in a world without choices and b) be fair, this particular mistake is on a third party port.

      Also c) other options are hardly without blemish. Apple has some nice phones, but when is the last time iOS had a problem? Say, bricking iPads? On an upgrade meant to fix a security hole?

      And they leave devices behind, too. There's an iPhone 4 in this house that only runs iOS 7, and a clutch of perfectly good 3GS phones that only run iOS 6. My Galaxy S4 only runs 5.0.1 stock, but at least I have the option of installing a third party port that brings it up to date.

      I don't entirely disagree. I just think that "pile of poo" might be a bit unfair. Also incomplete. Possibly disingenuous.

  6. Anonymous Coward
    Anonymous Coward

    Another day ..

    .. another Windows Android problem.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like