Scary Mediatek vulnerability active for months because Android updates are hard - Android

Get it on Google Play

Scary Mediatek vulnerability active for months because Android updates are hard - Android

It's been 10 months since this vulnerability became public knowledge. Who knows what damage has been done since then.

The MediaTek Helio P90 chipset.

Over at XDA Developers, Android enthusiasts tinker with the software that runs phones, tablets, and other pieces of tech. Primarily, modders are hobbyists who want to do simple things with their devices such as remove bloatware, flash a new ROM, or fix a broken phone.

However, one XDA modder came across an exploit in Mediatek chipsets — a lot of Mediatek chipsets. The modder was using this exploit to unlock the bootloaders of Amazon Fire tablets, which is a quite sought-after thing as doing so allows you to install the Google Play Store on Amazon’s cheap tablets.

Through a considerable amount of detective work, XDA realized that this exploit — nicknamed Mediatek-su — could potentially allow a malicious actor to do pretty much anything it likes on a victim’s smartphone. We’re talking everything from installing any apps they like, changing permissions for existing apps, and accessing private data. This discovery happened in early February.

After some further research, XDA concluded that Mediatek knew full well of this exploit nearly ten months ago. To that company’s credit, it released a patch for its chipsets to fix the vulnerability. However, Mediatek is not an OEM — it’s up to the manufacturer of a device to push that fix to its products.

Amazon, as one would expect, did just that. But Mediatek chips are used in hundreds of different smartphones and tablets from dozens of manufacturers. Many of these companies don’t have the resources or motivation to issue out Android updates, even ones as critical as this.

After figuring this all out, XDA went to Google.

Google decides to wait

google logo G at ces 20201

With the high level of danger related to Mediatek-su, XDA assumed Google would use its considerable weight to force OEMs to issue Mediatek’s patch. However, Google ultimately told XDA to hold off on publishing any information about the security vulnerability until today — the day that Google would release the Android Security Bulletin for March 2020. Google’s assumption was that if as few people as possible knew about the exploit until its scheduled patch went out then the danger would be mitigated.

Of course, Google could have also released a special bulletin for an exploit of this magnitude. This would have been more than appropriate when you consider that the exploit has already been around for months and likely already caused plenty of damage.

Regardless, it still falls on the OEMs to fully fix this problem, and many of them simply won’t do it. This, unfortunately, means that there are likely thousands (or possibly millions) of devices out there that are, as of right now, completely vulnerable to this exploit. That means things like ransomware, adware, and other extremely problematic software hacks could infect those devices to an alarming degree.

It should be noted that Mediatek chipsets are primarily used in mid-range and budget devices. That means people who can’t afford flagship phones are in the most danger.

To see if your phone or tablet is one of the devices affected by Mediatek-su, you can find a list in the original XDA article here.

More posts about Mediatek

Samsung Galaxy S10 5G 5G logo

How low will 5G phone prices go in 2020?

The MediaTek logo at the company's Hsinchu HQ.

MediaTek wants to bring gaming chipsets to very cheap phones (Update: Launched)

The MediaTek logo at the company's Hsinchu HQ.

MediaTek Dimensity 800 launched: 5G is starting to go mainstream

Qualcomm Snapdragon 865 in hand front

Qualcomm Snapdragon 865 vs MediaTek Dimensity 1000 specs: A rivalry renewed

MediaTek Dimensity 5G chipset.

Qualcomm has flagship competition: MediaTek Dimensity 1000 5G chipset announced

The MediaTek Helio M70 modem.

Intel’s solution for 5G laptops? Team up with MediaTek.

The MediaTek logo at the company's Hsinchu HQ.

The best MediaTek phones (November 2019)

MediaTek Helio M70 5G SoC

We just got a step closer to affordable 5G phones

mediatek helio g90 1

MediaTek Helio G90, G90T revealed: What to expect from its first gaming SoC?

The MediaTek Helio P65.

MediaTek Helio P65 announced: An overdue CPU upgrade, but what else? (Update)

02/03/2020 09:28 PM