Attention! If you are using a Xiaomi Mi or Redmi smartphone, you should immediately stop using the built-in MI browser or Mint browser available on the Google Play Store for non-Xiaomi Android devices
The two web browser apps created by Xiaomi are vulnerable to a critical vulnerability that has not yet been patched.
The vulnerability, identified as CVE-2019-10875 and discovered by security researcher Arif Khan, is an issue that causes browser URL spoofing due to a logical flaw in the browser environment, allowing a malicious website to control the URLs displayed in the address bar.
Since a web browser's address bar is the most trusted and key security indicator, the flaw can be used to easily mislead Xiaomi users into thinking they are visiting a trusted website, when in fact they are engaging in phishing or malicious content.

Phishing attacks today are more sophisticated and increasingly difficult to detect, and this URL spoofing vulnerability is quite concerning, allowing someone to bypass key indicators like URL and SSL, the first things a user checks to determine if a website is fake.
The strangest thing about the case is that it only affects the international variants of the two web browsers, even though the domestic versions distributed with Xiaomi smartphones in China do not contain this vulnerability.
This raises the reasonable question of whether Chinese manufacturers are intentionally leaving international users vulnerable through vulnerable OS, applications, and firmware.
Also, it's even more strange that Xiaomi rewarded the security researcher with a bug bounty, but has yet to fix the bug.
Whatever the outcome of the situation, Android users are strongly advised to use modern web browsers that are not affected by this vulnerability, such as Chrome or Firefox.
Besides, if you use Microsoft Edge or Internet Explorer browser on your desktop, you should also avoid using them, as both browsers contain a critical vulnerability that has not yet been patched by the giant.
