As we reported yesterday, a serious vulnerability in MediaTek chipsets left millions of Android smartphones. unprotected The company had released an update in May 2019, a month after the vulnerability was discovered, but phone manufacturers had not taken the time to implement it in their smartphones . Now, Google is releasing a patch to fix the vulnerability.
MediaTek is a very large chipmaker , designing chips for wireless communications, high-definition televisions, and devices such as smartphones and tablets .
The MediaTek error
The vulnerability was named MediaTek-SU (CVE-2020-0069) and was discovered by chance by members of the XDA developers forum.
The vulnerability has existed since April 2019, however attackers have started exploiting it and carrying out hacking campaigns recently.
As we said above, MediaTek immediately released an update to fix the vulnerability, however the update was not applied to smartphones and thus hackers were able to compromise the vulnerable phones and install a malicious application on the devices.
The exploit exists on almost all 64-bit MediaTek chipsets, affecting Motorola, OPPO, Sony, Alcatel, Amazon, ASUS, Blackview, Realme, Xiaomi and other devices.
Exploiting the vulnerability is a simple process. Users can run a script to gain superuser access to the shell, as well as set SELinux, the Linux kernel module that provides access control for various processes. Thus, by running the script, users can gain access elevated
Execution of the error
Since January 2020, Trend Micro has detected malicious spyware on Google Playthat use the MediaTek-SU vulnerability to compromise the devices of users who install them.
Now, the vulnerability is being patched by Google, along with other critical vulnerabilities, with the release of the Android Security bulletin for March 2020.
Another critical vulnerability being fixed is CVE-2020-0032 , which can execute malicious code and give access to victims' systems

