Vulnerabilities in MediaTek chips expose millions of Android devices to eavesdropping

app security
(Image credit: Shutterstock.com)

Cybersecurity researchers have uncovered multiple security flaws in chips made by Taiwanese manufacturer MediaTek found in 37% of the world’s smartphones, warning that some could be chained together to enable attackers to eavesdrop on unsuspecting users.

Check Point Research (CPR) found the security flaws inside the audio processor that’s used in all modern MediaTek mobile chips. 

CPR explained that MediaTek chips contain a special AI processing unit (APU) and audio Digital signal processor (DSP), both of which have custom microprocessor architectures. In order to find the degree to which MediaTek DSP could be used as an attack vector, CPR reverse engineered the MediaTek audio processor to reveal several security flaws. 

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

New attack vector

CPR brought the vulnerabilities to the attention of MediaTek, who has since patched the bugs.

Explaining how a threat actor could exploit the security vulnerabilities, CPR says a hypothetical attack would begin with the user installing a malicious Android app, which uses the MediaTek API to attack a library that has permissions to talk with the audio driver. 

The app, which has system privileges, sends crafted messages to the audio driver to execute code in the firmware of the audio processor, which enables it to capture the audio passing through the DSP.

“In summary, we proved out a completely new attack vector that could have abused the Android API. Our message to the Android community is to update their devices to the latest security patch in order to be protected,” says Slava Makkaveev, security researcher at Check Point Software.

Both CPR and MediaTek assert that they haven’t found any evidence of the vulnerability being exploited in the wild.

Meanwhile, if you are really concerned about privacy, you should consider using one of these best VPN or these best secure smartphones

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Photograph of a hand holding a smartphone with two googly eyes
Every tap, every message – how to stop your smartphone spying on you
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)