• Home
  • Phones
  • MediaTek security flaw may have affected more Android phones than initially reported
Image

MediaTek security flaw may have affected more Android phones than initially reported


MediaTek Dimensity 9400 chip on finger edited

Hadlee Simons / Android Authority

TL;DR

  • Security firm Trustonic has pushed back on claims that its software is vulnerable on MediaTek chips.
  • The issue could affect multiple security systems across MediaTek processors, not just Trustonic’s, the company told Android Authority.
  • MediaTek issued a fix in January, but the scope of affected devices is still unclear.

Don’t want to miss the best from Android Authority?

google preferred source badge light@2xgoogle preferred source badge dark@2x

The issue was discovered by Ledger’s Donjon security research team on the CMF Phone 1 by Nothing. Researchers were able to extract sensitive data, including the phone’s PIN and crypto wallet seed phrases, in under a minute without booting Android.

While Ledger suggested the issue stemmed from Trustonic’s Trusted Execution Environment (TEE) on MediaTek chips, Trustonic says the problem wasn’t in its security software.

“This issue does not exist on other SoC vendor products where we are using the same version of Kinibi,” the company told Android Authority.

For context, Kinibi is Trustonic’s secure software that runs inside a phone’s protected environment (TEE) and ensures sensitive data like PINs, encryption keys, and biometric information remain safe.

So, essentially, Trustonic is claiming that its software behaves securely on other chipsets and suggesting that the weakness is specific to MediaTek’s platform.

“Trustonic is not on all MediaTek chipsets, hence calling out Trustonic explicitly is not reasonable,” the company said.

While the original research held both MediaTek chips and Trustonic’s TEE responsible for the vulnerability, Trustonic’s response suggests the problem affected a wider range of Android devices across different brands and security implementations.

Trustonic added that it did not need to update its security software, as MediaTek issued the fix from its end to device makers on January 5, 2026.

The company declined to confirm whether the Nothing CMF Phone 1 uses its technology. We also reached out to Ledger’s Donjon team to clarify the scope of the issue, but did not hear back at the time of publication.

Thank you for being part of our community. Read our Comment Policy before posting.



Source link

Releated Posts

Google might be undoing some controversial changes to the Photos app

Joe Maring / Android Authority TL;DR Google is reversing some of the changes it made to the photo…

ByByTDSNEWS999 Mar 18, 2026

Pixel owners report freezing lock screens after March Pixel Drop

Joe Maring / Android Authority TL;DR Google Pixel owners have reported that their phones are freezing on the…

ByByTDSNEWS999 Mar 18, 2026

PSA: Those trendy rear screens won’t work with Pixels, because Google

TL;DR Google’s Pixel devices do not support those magnetically attaching wireless displays you might have seen in the…

ByByTDSNEWS999 Mar 18, 2026

The Galaxy Z TriFold is dead, and it’s all Samsung’s fault

Lanh Nguyen / Android Authority Just three months after its debut, the Samsung Galaxy Z TriFold is already…

ByByTDSNEWS999 Mar 18, 2026