MediaTek Chip Vulnerability Exposes Android Phones Patch Issued in January

 MediaTek Chip Vulnerability Exposes Android Phones Patch Issued in January

Researchers at Ledger Donjon say a vulnerability in MediaTek's Dimensity and Helio chipsets could allow attackers to access Android smartphones within minutes of connection by targeting the Trustonic TEE, a trusted execution environment that protects sensitive user data. The flaw, if present across affected devices, could let intruders reach a phone's security PIN, decrypted storage, and seed phrases for popular cryptocurrency wallets. Ledger's post on X cites testing on the CMF Phone 1 powered by a Dimensity 7300, with security access achieved 45 seconds after the device was plugged into a computer. MediaTek has said a patch was issued to device makers in January, but it remains unclear whether all affected devices have been updated. OEMs have not publicly acknowledged the vulnerability as of publication.

The vulnerability is described as stemming from the Trustonic TEE used by MediaTek's Dimensity and Helio series. The research group reported that it could breach the phone's protection and access the security PIN, decrypt storage, and extract seed phrases used by popular software wallets for cryptocurrency verification and account recovery. The findings, presented by Ledger Donjon, heighten concerns about the security of Android devices powered by MediaTek chips when the trusted execution environment is compromised.

Discovery and Affected Devices

In a post on X, Ledger Donjon researchers say they tested the vulnerability on the CMF Phone 1, a device equipped with the Dimensity 7300 chipset. They report that the breach occurred within 45 seconds of the device being connected to a computer, and that the attacker could recover sensitive data without turning on the phone in some scenarios. The group notes the issue appears to stem from the Trustonic TEE used on MediaTek's Dimensity and Helio lines, which is intended to protect sensitive data on Android handsets.

Patch Status and Security Landscape

As of publication, OEMs have not publicly acknowledged the vulnerability. MediaTek told Android Authority that it issued a patch for the vulnerability to device makers as early as January; it is not known whether all affected devices have received the patch. Ledger's claims imply a potentially wide impact, with millions of Android phones powered by MediaTek chips possibly at risk. By contrast, smartphones from other brands, including Google and Apple, and devices built on Snapdragon chips, are described as having dedicated security chips that protect user information.

Technical Details

  • Chipsets involved: MediaTek Dimensity and Helio series
  • Security environment: Trustonic TEE
  • Test device cited: CMF Phone 1
  • Chip tested: Dimensity 7300
  • Time to breach observed: 45 seconds after connection
  • Data potentially exposed: security PIN, decrypted storage, seed phrases for cryptocurrency wallets
  • Phone state during breach: data could be recovered even if the phone was not turned on
  • Patch status: patch issued to device makers in January; impact scope unclear
  • OEM response: no public acknowledgment fromOEMs as of publication
  • Security landscape contrast: other brands are said to use dedicated security chips

No additional details are provided beyond the claims and the patch note from MediaTek. The situation remains under observation as OEMs, and independent researchers await further verification and potential updates.