HomeSecurityGoogle fixes critical vulnerability in MediaTek chips

Google fixes critical vulnerability in MediaTek chips

As we reported yesterday, a serious vulnerability in MediaTek chipsets left millions of Android smartphones. unprotected The company had released an update in May 2019, a month after the vulnerability was discovered, but phone manufacturers had not taken the time to implement it in their smartphones . Now, Google is releasing a patch to fix the vulnerability.

MediaTek is a very large chipmaker , designing chips for wireless communications, high-definition televisions, and devices such as smartphones and tablets .

The MediaTek error

The vulnerability was named MediaTek-SU (CVE-2020-0069) and was discovered by chance by members of the XDA developers forum.

The vulnerability has existed since April 2019, however attackers have started exploiting it and carrying out hacking campaigns recently.

As we said above, MediaTek immediately released an update to fix the vulnerability, however the update was not applied to smartphones and thus hackers were able to compromise the vulnerable phones and install a malicious application on the devices.

Google-competitors data-apps

The exploit exists on almost all 64-bit MediaTek chipsets, affecting Motorola, OPPO, Sony, Alcatel, Amazon, ASUS, Blackview, Realme, Xiaomi and other devices.

Exploiting the vulnerability is a simple process. Users can run a script to gain superuser access to the shell, as well as set SELinux, the Linux kernel module that provides access control for various processes. Thus, by running the script, users can gain access elevated

Execution of the error

Since January 2020, Trend Micro has detected malicious spyware on Google Playthat use the MediaTek-SU vulnerability to compromise the devices of users who install them.

Now, the vulnerability is being patched by Google, along with other critical vulnerabilities, with the release of the Android Security bulletin for March 2020.

Another critical vulnerability being fixed is CVE-2020-0032 , which can execute malicious code and give access to victims' systems

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS