Thedefiant MediaTek Chip Vulnerability Exposes 25% of Android Phones to Data Theft
Article Content
- •Vulnerability allows data extraction from Android phones in under 45 seconds.
- •Approximately 25% of Android devices using MediaTek chips are affected.
- •MediaTek has released a firmware patch to address the vulnerability.
A critical vulnerability affecting MediaTek processors in Android smartphones allows attackers to extract sensitive user data, including PINs and cryptocurrency wallet seed phrases, in under 45 seconds. Discovered by Ledger's Donjon security team, the flaw exploits weaknesses in the secure boot chain of affected devices, enabling unauthorized access via a USB connection. This vulnerability could impact approximately 25% of Android phones globally, particularly those utilizing Trustonic's Trusted Execution Environment (TEE). The issue has been publicly disclosed as CVE-2026-20435, and MediaTek has issued a firmware patch to device manufacturers. Users are advised to ensure their devices are updated with the latest security patches to mitigate risks. The vulnerability has been present for potentially a decade without prior detection. Ledger's CTO emphasized the need for improved security in smartphones, which are often not designed to safeguard sensitive data effectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (23)
Following this threat?
Track Ledger and CVE-2025-20435 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…