
DEF CON 32 - Xiaomi The Money : Our Toronto Pwn2Own Exploit & BTS Story - Ken Gannon, Ilyes Beghdadi
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 39:03
The team successfully exploited a zero-day vulnerability in the Xiaomi 13 Pro’s Get Apps app via a web view XSS to achieve remote code execution, ultimately succeeding in Spain due to region-specific app availability 1:58.
Key Takeaways:
• The exploit used a web view XSS in Get Apps to inject malicious JavaScript, bypassing input sanitization in the integral_dialog_page.chunk.js file 13:00.
• A JavaScript interface allowed execution of the install and openApp functions, enabling force-installation of any app without user consent 9:00.
• The attack chain was completed by installing a reskinned Drozer app (Sunfish) and establishing a bind shell, achieving full remote code execution 18:00.
• The exploit worked only in Spain, where the Opera browser was enabled and the app store was not yet launched, while failing in the Philippines, Canada, and the US due to region-specific restrictions 33:00.
• Xiaomi patched the vulnerability by removing the exploited file from the app, blocking app installations, and adding browser restrictions, leading to a failed attack during the competition 36:00.
Xiaomi’s aggressive patching and lack of vendor acknowledgment resulted in no CVE credit for the team, highlighting poor vendor response. 38:00
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right hello I'm not used to a mic so sensitive so I'm going to talk like back here and if that doesn't work then I'll adjust whatever this is xiaomi the money the our P Toronto pwn to own 2023 exploit and behind the scenes story uh what this talk is about is our hack against the xiaomi 13 Pro which includes the full exploit chain that we used and also issues encountered during the research itself and then we're we're going to cover what happened during the Pawn's own competition itself and for a little bit of background on who we are I'm Ken Ganon I'm a principal security consultant at NCC group and I usually focus on hacking mobile [ __ ] this is ilas at the time of the competition he was also part of NCC group he is a veteran Android malware reverse engineer and this was his first ti…