875 Million Android Phones Put At Risk From This 60 Second Hack

by Marcus Liu - Business Editor
0 comments

Android Security Flaw: 875 Million Phones at Risk of Hack

A critical security vulnerability affecting approximately 875 million Android phones has been discovered, allowing attackers to potentially gain access to locked devices in under a minute. The flaw, primarily impacting budget handsets, centers around a weakness in MediaTek SoCs (System-on-a-Chip) utilizing Trustonic’s TEE (Trusted Execution Environment).

How the Hack Works

Researchers at Donjon, the research division of crypto security hardware company Ledger, demonstrated the exploit by connecting a vulnerable phone to a laptop via USB. This allowed them to recover the handset PIN, decrypt storage, and extract seed phrases from software wallets [ZDNET]. The vulnerability, tracked as CVE-2026-20435, bypasses standard security measures like full-disk encryption and lock screens.

Which Phones Are Affected?

The vulnerability impacts roughly one in four Android phones, with the majority being lower-cost models. The issue stems from a flaw in Trustonic’s TEE and MediaTek chips. To determine if your device is affected, check your phone’s SoC on platforms like GSMArena or your vendor’s website and cross-reference it with MediaTek’s March Security bulletin under CVE-2026-20435 [Malwarebytes].

What Has Been Done to Fix the Problem?

MediaTek has released a firmware patch that device manufacturers can integrate into security updates. However, the rollout of these updates varies significantly depending on the manufacturer and the device’s end-of-life (EOL) cycle. Some devices may receive updates quickly, although others may never be patched [Malwarebytes].

What Can You Do?

  • Retain Your Phone Secure: While the vulnerability is technical, the most basic security advice remains crucial: keep a close eye on your phone to prevent loss or theft.
  • Install Updates: Ensure your device is running the latest security updates from your manufacturer.
  • Check Your SoC: Verify if your phone uses an affected MediaTek chip using resources like GSMArena.

Looking Ahead

This vulnerability highlights the growing threat of hardware-level security flaws in mobile devices. As cybercrime targeting hardware increases, manufacturers and security researchers must prioritize proactive security measures to protect user data. The incident underscores the importance of timely security updates and the potential risks associated with older, unsupported devices.

Sources:

Related Posts

Leave a Comment