Software Bug Leaves Several MediaTek-Powered Android Devices Vulnerable to Attack

Advertisement
By Manish Singh | Updated: 1 February 2016 16:46 IST

Several Android smartphones and tablets powered by MediaTek chipsets are vulnerable to security attacks due to a software bug. The flaw, if exploited, allows an attacker to glean private data including photos, contacts, and even remotely monitor all traffic. The chipmaker confirmed the existence of the vulnerability to Gadgets360, and added that its security team is currently working on the issue.

Justin Case, a security researcher reported about the vulnerability on Twitter earlier this month. Explaining the vulnerability, Case told Gadgets360 that MediaTek software has a "backdoor" that allows a user - or a malicious app - to enable root access. The problem, as Case explained, is a user or a malicious app can change the usually restricted and read only properties on the device, which "can trivially lead to privilege escalation to the root user."

Advertisement

"Root user could do many things, such as access data normally protected from the user/ other apps, or brick the phone, or spy on the user, monitor communications etc," Case told Gadgets 360 over email.

Taiwan-based MediaTek, whose chips power several popular Android phones, told us that the vulnerability exists on devices running Android 4.4 KitKat. Explaining how the vulnerability got there in the first place, MediaTek said that a debug feature was created for telecommunication inter-operability testing mainly in China. The smartphone manufacturers, however, didn't disable the debug feature before shipping the smartphones, the company added. MediaTek didn't disclose the names of the manufacturers.

Advertisement

"We are aware of this issue and it has been reviewed by MediaTek's security team. It was mainly found in devices running Android 4.4 KitKat, due to a de-bug feature created for telecommunication inter-operability testing in China," a MediaTek spokesperson told Gadgets 360 in an emailed statement. "After testing, phone manufacturers should disable the de-bug feature before shipping smartphones. However, after investigation, we found that a few phone manufacturers didn't disable the feature, resulting in this potential security issue."

Case noted that read-only properties - ro.properties - should not change after booting the device, however, MediaTek has "'nerved' the property space, they made it so these properties can be changed, and changed by anyone/app. A malicious app could set the 'ro.secure' property to 0, ro.debuggable one to 1, ro.adb.secure prop to 0 (this would mean ADB didn't need authentication) and then enable the ADB over Wi-Fi property, and get a local root shell."

Advertisement

MediaTek declined to specify the smartphone models and the number of handsets that are impacted. The company insists that the issue only affects certain manufacturers and it has begun to alert them. "While this issue affected certain manufacturers, it also only affected a portion of devices for those manufacturers. We have taken steps to alert all manufacturers and remind them of this important feature."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, MediaTek, Security, Vulnerability
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11 Ultra Will Launch With This Custom MediaTek SoC
  2. Vivo's New S50t Vitality Edition Packs a Snapdragon 8s Gen 3 Chipset
  3. Samsung Galaxy S26 FE, Galaxy Tab S12+ and Galaxy A07s Spotted on Google Play Console
  4. Vivo Y6k Could Launch as Rebranded Vivo Y-Series Smartphone
  5. Here's When the Google Fitbit Air Will Launch in India
  6. Realme 16x 5G Goes on Sale in India With These Offers
  7. OTT Releases This Week: Cocktail 2, Bharat Bhhagya Viddhaata, and More
  8. Honor Magic 9 Series Launch Date, Key Specs Tipped Online
  9. Google Pixel 11 vs iPhone 17: Price in India and Specifications Compared
  10. Samsung Galaxy S26 Series Gets Up to Rs. 30,500 Discount in Freedom Sale
  1. Samsung Galaxy S26 FE, Galaxy Tab S12+ and Galaxy A07s Spotted on Google Play Console
  2. Vivo X500 Pro Max Reportedly Bags 3C Certification, Charging Speed Revealed
  3. CD Projekt Red Confirms Layoffs at Project Sirius Witcher Multiplayer Spinoff
  4. Xiaomi’s Next Foldable Leaked With Wider Screen Ahead of Expected September Launch
  5. Metaplanet Denies BTC Liquidation as Bitcoin Falls Below Company's Average Cost
  6. iQOO Neo 11 Ultra Confirmed to Launch With a Custom MediaTek Chipset With New 'Monster' Super Core Engine
  7. Honor Magic 9 Series Launch Confirmed; Launch Date, Camera Details Tipped Online
  8. Apple Reportedly Secures Better Deal for iPhone 18 Pro Series’ OLED Panels; iPhone 18 Leak Hints at New Upgrades
  9. Vivo Y6k Reportedly Spotted on Google Play Console; Could Arrive as Another Rebranded Y-Series Model
  10. BGMI Redeem Codes for August 13 Released: How to Claim Smiling Pal Backpack, Other Free Rewards
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.