Safety researchers have realized a couple of vulnerability in Android telephones with MediaTek chipsets. This vulnerability permits attackers to retrieve delicate consumer information even when the machine is powered off.
The flaw was found by Donjon, a {hardware} safety analysis workforce run by the corporate Ledger. In accordance with Android Authority, the vulnerability may have an effect on hundreds of thousands of gadgets with MediaTek chips that use Trustonic’s Trusted Execution Atmosphere (TEE). The Donjon workforce used the CMF Telephone 1 by Nothing to showcase the exploit and gained entry to the consumer’s information in lower than a minute.
The Ledger Donjon plugged a Nothing CMF Telephone 1 right into a laptop computer and breached the cellphone’s foundational safety inside 45 seconds.
This has the potential to have an effect on hundreds of thousands of Android smartphones utilizing Trustonic’s TEE and MediaTek processors.— Charles Guillemet (@P3b7_) March 11, 2026
Even when your machine is turned off, a hacker can break into it, retrieve the machine’s PIN, decrypt its storage, and extract the grasp keys used to get better crypto wallets.
AA stories that plenty of MediaTek gadgets depend on a Trusted Execution Atmosphere (TEE), which is an space throughout the processor that protects delicate information. As compared, Pixel gadgets with Tensor, iPhones and plenty of Snapdragon handsets have their very own devoted {hardware} safety processors to guard delicate info. Telephones with devoted {hardware} are higher at defending the {hardware} from bodily assaults.
The Donjon workforce says it knowledgeable MediaTek in regards to the vulnerability earlier than reporting it to the general public. And MediaTek informed the safety analysis agency that it offered fixes to machine producers on January 5, 2026, that means that the vulnerability needs to be mounted when affected cellphone makers launch a software program replace.
The Donjon workforce had beforehand found a fault throughout the MediaTek Dimensity 7300 chipset final 12 months as effectively.
Supply: Android Authority, Donjon workforce run by Ledger
MobileSyrup could earn a fee from purchases made through our hyperlinks, which helps fund the journalism we offer free on our web site. These hyperlinks don’t affect our editorial content material. Assist us right here.
Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s developments at the moment: learn extra, subscribe to our e-newsletter, and grow to be a part of the NextTech neighborhood at NextTech-news.com

