{"id":531440,"date":"2026-03-18T20:13:14","date_gmt":"2026-03-18T20:13:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/531440\/"},"modified":"2026-03-18T20:13:14","modified_gmt":"2026-03-18T20:13:14","slug":"mediatek-security-flaw-may-have-affected-more-android-phones-than-initially-reported","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/531440\/","title":{"rendered":"MediaTek security flaw may have affected more Android phones than initially reported"},"content":{"rendered":"<p><img class=\"e_lg\" decoding=\"async\" loading=\"eager\"  title=\"MediaTek Dimensity 9400 chip on finger edited\"  alt=\"MediaTek Dimensity 9400 chip on finger edited\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2026\/03\/MediaTek-Dimensity-9400-chip-on-finger-edited-scaled.jpg\"\/><\/p>\n<p>Hadlee Simons \/ Android Authority<\/p>\n<p>TL;DR<\/p>\n<p>Security firm Trustonic has pushed back on claims that its software is vulnerable on MediaTek chips.<br \/>\nThe issue could affect multiple security systems across MediaTek processors, not just Trustonic\u2019s, the company told Android Authority.<br \/>\nMediaTek issued a fix in January, but the scope of affected devices is still unclear.<\/p>\n<p>Don\u2019t want to miss the best from Android Authority?<\/p>\n<p><a href=\"https:\/\/andauth.co\/AAGooglePreferredSource\" class=\"e_nm\" target=\"_blank\" rel=\"noreferrer nofollow noopener\"><img class=\"e_lg\" decoding=\"async\" loading=\"lazy\"  title=\"google preferred source badge light@2x\"  alt=\"google preferred source badge light@2x\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2026\/01\/google_preferred_source_badge_light@2x.png\"\/><img class=\"e_lg\" decoding=\"async\" loading=\"lazy\"  title=\"google preferred source badge dark@2x\"  alt=\"google preferred source badge dark@2x\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2026\/01\/google_preferred_source_badge_dark@2x.png\"\/><\/a><\/p>\n<p>The issue was discovered by Ledger\u2019s Donjon security research team on the <a href=\"https:\/\/www.androidauthority.com\/nothing-cmf-phone-1-review-3502896\/\" rel=\"nofollow noopener\" target=\"_blank\">CMF Phone 1<\/a> by Nothing. Researchers were able to extract sensitive data, including the phone\u2019s PIN and crypto wallet seed phrases, in under a minute without booting Android.<\/p>\n<p>While Ledger suggested the issue stemmed from Trustonic\u2019s Trusted Execution Environment (TEE) on MediaTek chips, Trustonic says the problem wasn\u2019t in its security software.<\/p>\n<p>\u201cThis issue does not exist on other SoC vendor products where we are using the same version of Kinibi,\u201d the company told Android Authority.<\/p>\n<p>For context, Kinibi is Trustonic\u2019s secure software that runs inside a phone\u2019s protected environment (TEE) and ensures sensitive data like PINs, encryption keys, and biometric information remain safe.<\/p>\n<p>So, essentially, Trustonic is claiming that its software behaves securely on other chipsets and suggesting that the weakness is specific to MediaTek\u2019s platform.<\/p>\n<p>\u201cTrustonic is not on all MediaTek chipsets, hence calling out Trustonic explicitly is not reasonable,\u201d the company said.<\/p>\n<p>While the original research held both MediaTek chips and Trustonic\u2019s TEE responsible for the vulnerability, Trustonic\u2019s response suggests the problem affected a wider range of Android devices across different brands and security implementations.<\/p>\n<p>Trustonic added that it did not need to update its security software, as MediaTek issued the fix from its end to device makers on January 5, 2026.<\/p>\n<p>The company declined to confirm whether the Nothing CMF Phone 1 uses its technology. We also reached out to Ledger\u2019s Donjon team to clarify the scope of the issue, but did not hear back at the time of publication.<\/p>\n<p>Thank you for being part of our community. Read our\u00a0<a class=\"c-link\" href=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-stringify-link=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" data-sk=\"tooltip_parent\">Comment Policy<\/a> before posting.<\/p>\n","protected":false},"excerpt":{"rendered":"Hadlee Simons \/ Android Authority TL;DR Security firm Trustonic has pushed back on claims that its software is&hellip;\n","protected":false},"author":2,"featured_media":531441,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[4329,133935,74],"class_list":{"0":"post-531440","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-android","9":"tag-mediatek","10":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/531440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=531440"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/531440\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/531441"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=531440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=531440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=531440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}