Bug Bounties

Xiaomi

Powered by: 

Allows bounty splitting: 

Average time to first program response: 52

Average time to bounty awarded null: 382

Average time to report resolved: 2784

Handle xiaomi

Managed program: false

Name: Xiaomi

Offers bounties: true

Offers swag: false

Response efficiency percentage: 76

Submission state: open

Url: https://hackerone.com/xiaomi

Website: http://www.mi.com

In scope:

  • Asset identifier: *.mi.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.miui.com
  • Asset type: URL
  • Availability requirement: medium
  • Confidentiality requirement: medium
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: medium
  • Max severity: critical



  • Asset identifier: *.miwifi.com
  • Asset type: URL
  • Availability requirement: medium
  • Confidentiality requirement: medium
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: medium
  • Max severity: critical



  • Asset identifier: *.xiaomi.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.xiaomiyoupin.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: MIUI OS for Xiaomi Phone
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: MIUI is Xiaomi phone operation system (OS), custimized on stock android. the scope inculdes the pre-installed apps with Xiaomi certification signed.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: Mi Band
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: mi-band-3/4/5
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi Electric Scooter
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://www.mi.com/us/mi-electric-scooter/
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi Home Webcam
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://www.mi.com/us/mi-home-security-camera/ , https://www.mi.com/in/camera-360/
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi Laser Projector
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://www.mi.com/us/mi-laser-projector-150/
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi Robot Vacuum
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction:  https://www.mi.com/hk/mi-robot-vacuum/
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi TV
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://store.mi.com/in/accessories/213
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi TV Box
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://www.mi.com/us/mi-box-s/
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Mi/Redmi Phone
  • Asset type: HARDWARE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://www.mi.com/hk/mi-note-10/,https://www.mi.com/hk/mi-a3/,https://www.mi.com/hk/max3/,https://www.mi.com/hk/mi-8-pro/,https://www.mi.com/hk/redmi-note-8-t/,https://www.mi.com/hk/redmi-note-8-pro/
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: Other APK Assets
  • Asset type: OTHER
  • Availability requirement: medium
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: com.miui.screenrecorder com.android.providers.telephony com.android.dynsystem com.miui.powerkeeper com.xiaomi.miplay_client com.milink.service com.xiaomi.mi_connect_service com.android.updater com.miui.securityadd/com.miui.gallery/com.android.mms.service/com.miui.msa.global/com.android.browser/com.miui.videoplayer/com.android.soundrecorder/com.miui.backup/com.miui.notification/com.android.certinstaller/com.miui.huanji/com.miui.hybrid/com.miui.vsimcore/com.miui.securitycore/com.mi.health/com.xiaomi.simactivate.service/com.miui.phrase/com.miui.player/com.miui.miservice/com.android.provision/com.miui.system/com.miui.global.packageinstaller/com.miui.compass/com.miui.cit/com.miui.android.fashiongallery/com.miui.bugreport/com.android.fileexplorer/com.android.camera/com.xiaomi.glgm/com.xiaomi.xmsf/com.miui.mishare.connectivity/com.miui.freeform/com.xiaomi.finddevice/com.mi.global.bbs/com.xiaomi.joyose/com.mi.android.globalFileexplorer/com.miui.notes/com.miui.wmsvc/com.xiaomi.midrop/com.miui.touchassistant/com.miui.miwallpaper/com.xiaomi.bluetooth/com.miui.cleanmaster/com.miui.analytics/com.android.settings/com.xiaomi.scanner/com.android.phone/com.android.deskclock/com.android.systemui/com.xiaomi.discover/com.android.thememanager/com.android.bluetooth/com.miui.face/com.miui.home
  • Integrity requirements: low
  • Max severity: high



  • Asset identifier: Other Hardware Assets
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Accepted ranges of hardware in Xiaomi’s Program include Xiaomi and Mijia products ( these are for assets that are not specified in the Hardware/IoT scope list )
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.android.browser
  • Asset type: OTHER_APK
  • Availability requirement: medium
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: high



  • Asset identifier: com.mi.global.shop
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.miui.cloudbackup
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.miui.cloudservice
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.miui.micloudsync
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.xiaomi.account
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.xiaomi.market
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.xiaomi.mibrain.speech
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.xiaomi.micloud.sdk
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.xiaomi.mipicks
  • Asset type: OTHER_APK
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.xiaomi.payment
  • Asset type: OTHER_APK
  • Availability requirement: 
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.xiaomi.smarthome
  • Asset type: OTHER_APK
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical