Xiaomi told 500 million users their private browsing was private. Researchers caught the Redmi Note 8 recording every URL, every search, every news click in incognito mode and shipping it to servers whose domains are registered in Beijing. The data was "encrypted" with base64 — a researcher decoded it in seconds. When Forbes showed Xiaomi the video proof, the company denied it. They later added an opt-out toggle. The default stayed opt-in.
high
Xiaomi told Lithuania it never censors users. Lithuania's cyber security agency found a list of 449 banned phrases — "Free Tibet," "democracy movement," "Long live Taiwan independence" — automatically downloaded to the Mi Browser on European phones. The censorship was switched off but could be remotely activated without anyone knowing. Lithuania's Defence Ministry told the entire nation: throw your Chinese phones away. Over 200 government agencies had already bought thousands of them.
high
Xiaomi says it provides no backdoor to any government. Chinese law says every Chinese company must "support, assist, and cooperate with national intelligence work." There is no opt-out clause. There is no judicial oversight. There is no transparency requirement that would reveal compliance. A Beijing-headquartered company promising independence from Beijing is making a promise Chinese law forbids it from keeping.
Xiaomi's app uses a special system-level permission to read your phone's unique identity numbers (IMEI, SIM info). The privacy policy mentions collecting these numbers but doesn't tell you the app has deeper access to your phone than normal apps are allowed.
high
Xiaomi gives you a button to turn off data collection, but researchers proved that turning it off doesn't actually stop your phone from reporting what apps you use and how long you use them.
high
Xiaomi's privacy policy never mentions that your phone has a hidden feature that can filter out political content about Tibet, Taiwan, and democracy — and Xiaomi can turn this censorship on remotely without telling you.
Researchers proved that the laser navigation sensor in robot vacuums like this one can be turned into a makeshift microphone that picks up conversations. While this requires the vacuum to be hacked first, known security flaws in the Xiaomi app and the vacuum's own software make that more possible than you might think. Xiaomi never mentions this risk.
critical
Your vacuum has a high-resolution camera that photographs the inside of your home every time it cleans. Xiaomi's privacy policy says nothing about these photos — where they're stored, who can see them, how long they're kept, or how to delete them. You have no way to even see what your vacuum has photographed.
high
The vacuum creates detailed maps of your home and takes photos during every cleaning cycle, but Xiaomi's privacy policy never tells you this data is being collected or sent to their servers. Security researchers proved the vacuum works perfectly fine without sending any data to the cloud, so this data collection serves Xiaomi's interests, not yours.
Xiaomi says it only collects data it needs, but the app for this fitness band can read your text messages, access your camera, record through your microphone, and read your contacts. None of these are needed to track your heart rate or count your steps.
high
Xiaomi says your data stays in your region, but the fitness band's app sends data to Xiaomi's advertising and tracking servers. Xiaomi is a Chinese company legally required to cooperate with Chinese intelligence services if asked — meaning your heart rate, sleep, and exercise data could be accessed by a foreign government no matter where you live.
high
The fitness band collects detailed health data — your heart rate every minute, blood oxygen levels, how you sleep, your stress levels, and menstrual cycles. Independent researchers found that Xiaomi scores among the worst of all fitness tracker companies for protecting this data, and there are no rules limiting how long they keep it.
Xiaomi doesn't tell you that your air purifier data gets combined with data from every other Xiaomi device you own. Your air quality readings plus your fitness tracker data plus your camera footage plus your smart plug schedules paint a complete picture of your life at home. And all of this combined data flows through an app with advertising trackers from ByteDance and Facebook.
high
The app that controls your air purifier asks for permission to use your phone's camera, microphone, and read your phone call information. An air purifier doesn't need any of these — it just needs to turn a fan on and off and show you air quality numbers.
high
Your air purifier's sensors can tell when you're home, when you're sleeping, when you're cooking, and roughly how many people are in the room — just from air quality changes. This data goes to Xiaomi's servers in Beijing, where Chinese law allows the government to access it. Your air purifier is essentially an occupancy sensor for your home.
Xiaomi says they only collect what's necessary, but their smart home app demands access to your phone's unique hardware IDs, microphone, infrared transmitter, and the ability to launch activities in the background — plus it has 8 tracking libraries built in, including advertising networks from ByteDance and Tencent. Managing a smart plug doesn't require any of this.
high
Xiaomi says they don't sell your data, but independent investigations found they send up to 61 types of information to Chinese servers, track your web browsing even in private mode, and have been hit with GDPR complaints across Europe for illegally transferring data to China. Saying 'we don't sell data' while transmitting it to servers in Beijing and Singapore is misleading at best.
high
The Xiaomi Home app asks for access to your camera, microphone, infrared transmitter, and privileged phone hardware IDs — none of which are needed to turn your smart lights on and off. It also includes advertising code from ByteDance (TikTok's parent company). Your smart home remote control app shouldn't be an advertising platform.