HT TECH wants to start sending you push notifications. Click allow to subscribe

Bug in MediaTek chips could lead to hackers eavesdropping on Android users

Upon research, CPR researchers found out that MediaTek chips, that power 37% of the world’s smartphones including the ones from companies like Xiaomi, Oppo, Realme, and Vivo among others, have security flaws inside the chip's audio processor.

By: HT TECH
Updated on: Nov 25 2021, 13:18 IST
MediaTek has already fixed these vulnerabilities on all the smartphones running on its SoCs. (MediaTek)

Time and again, we heard reports about zero-day vulnerabilities that could give hackers the necessary means to gain access to people’s PC, smartphones or even smart home devices. Reports have also detailed how hackers use malicious apps to gain access to people’s smartphones. Now, reports have detailed a bug that could lead hackers to eavesdrop on Android users.

Researchers from Check Point Research have identified security flaws in the smartphone chip made by Taiwanese manufacturer MediaTek. Upon research, CPR researchers found out that MediaTek chips, that power 37% of the world’s smartphones including the ones from companies like Xiaomi, Oppo, Realme, and Vivo among others, have security flaws inside the chip’s audio processor. If left unpatched, the vulnerabilities could have enabled a hacker to eavesdrop on an Android user and hide malicious code on the MediaTek-powered devices.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

The report also detailed the process that hackers would have to go through to exploit this vulnerability. First of all, a user will have to install and launch a malicious app from the Google Play Store to give hackers a way to exploit the vulnerability in MediaTek SoC-powered smartphones. Once installed and launched, the app will use the MediaTek API to attack a library that has permission to talk with the audio driver. After that, the malicious app with system privilege will send crafted messages to the audio driver to execute code in the firmware of the audio processor. Once that happens, the app will steal the audio flow enabling hackers to eavesdrop on a users’ conversations.

CPR in a blog post noted that this hack could be executed via three separate vulnerabilities, which include CVE-2021-0661, CVE-2021-0662, and CVE-2021-0663. Soon after, CPR researchers disclosed their findings to MediaTek, which fixed these vulnerabilities in October.

To put it simply, MediaTek has already fixed these vulnerabilities on all the smartphones running on its SoCs. All you need to do is ensure that you have downloaded the latest firmware and software update on your smartphone.

“Device security is a critical component and priority of all MediaTek platforms. Regarding the Audio DSP vulnerability disclosed by Check Point, we worked diligently to validate the issue and make appropriate mitigations available to all OEMs. We have no evidence it is currently being exploited. We encourage end-users to update their devices as patches become available and to only install applications from trusted locations such as the Google Play Store,” Tiger Hsu, Product Security Officer at MediaTek said in a statement.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 25 Nov, 12:19 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
53% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹21,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
24% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,699₹12,700
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
23% OFF
HP Envy 13 X360 13 ag0035au 5FP71PA Laptop
  • Dark Ash Silver
  • 8 GB RAM
  • 256 GB SSD
₹69,990₹90,486
Buy now
44% OFF
Asus ROG Flow X13 GV301RE LI201WS Laptop
  • Off Black
  • 32 GB RAM
  • 1 TB SSD
₹84,990₹152,990
Buy now
11% OFF
MSI Summit E14 Flip Intel Evo A13MT 278IN Laptop
  • Black
  • 16 GB RAM
  • 1 TB SSD
₹114,990₹128,990
Buy now
NEXT ARTICLE BEGINS