Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
MediaTek Chip Flaw Exposes Android PINs in Seconds

MediaTek Chip Flaw Exposes Android PINs in Seconds

Posted on March 12, 2026 By CWS

A newly discovered vulnerability in the MediaTek Dimensity 7300 chipset has raised significant security concerns. This flaw allows physical attackers to extract device PINs, decrypt storage, and access cryptocurrency wallet seed phrases in under a minute. Approximately 25% of Android users are potentially at risk due to their devices’ reliance on this chipset.

Discovery of the Vulnerability

The security flaw was identified by Ledger’s Donjon research team, who pinpointed it in the Boot ROM of the MediaTek Dimensity 7300 chip. This component executes the first code when a device starts, operating at the highest hardware privilege level before the Android system loads.

Because the Boot ROM is permanently embedded in the chip’s silicon, this core vulnerability cannot be fixed with a software update. However, Ledger’s team demonstrated the potential impact by using Electromagnetic Fault Injection (EMFI), a technique that disrupts the chip’s operations with timed electromagnetic pulses. This method allows attackers to bypass security layers and execute arbitrary code at the highest privilege level.

Impact on Android Devices

Ledger’s proof-of-concept was conducted on a Nothing CMF Phone 1, which was compromised within 45 seconds. This demonstration showed that attackers could retrieve the device PIN, decrypt data, and access seed phrases from multiple cryptocurrency wallets.

The vulnerability impacts various applications, including Trust Wallet, Kraken Wallet, and others. Despite a low success rate per attempt, the attack can be automated and repeated, making it a practical threat to devices using the MediaTek Dimensity 7300 and Trustonic’s Trusted Execution Environment (TEE).

Response and Mitigation

Following the disclosure of this vulnerability, MediaTek released a security patch in January 2026 to mitigate exploitation pathways, though it does not address the underlying hardware flaw. MediaTek has stated that EMFI attacks were not anticipated in the design of the MT6878 chipset.

Charles Guillemet, CTO of Ledger, emphasized the importance of transferring sensitive data to hardware wallets with certified security features. He warned that smartphones are not designed to serve as secure storage for critical information, such as private keys and seed phrases.

The affected devices include those from brands like Realme, Motorola, and Oppo, which use the MediaTek Dimensity 7300. Users are advised to apply available security patches and consider additional protective measures for their digital assets.

Stay informed with our daily updates on cybersecurity by following us on Google News, LinkedIn, and X. For more information or to share your stories, contact us.

Cyber Security News Tags:Android security, chip vulnerability, Cryptocurrency, Cybersecurity, EMFI, hardware flaw, Ledger, MediaTek, PIN theft, smartphone security, TEE

Post navigation

Previous Post: Critical Flaw in Ally Plugin Puts 200,000 WordPress Sites at Risk
Next Post: Critical Vulnerabilities Patched by Splunk and Zoom

Related Posts

Microsoft Patch Tuesday January 2026 Microsoft Patch Tuesday January 2026 Cyber Security News
Microsoft Enhances Windows Security with Memory Integrity Microsoft Enhances Windows Security with Memory Integrity Cyber Security News
Chinese Salt Typhoon and UNC4841 Hackers Teamed Up to Attack Government and Corporate Infrastructure Chinese Salt Typhoon and UNC4841 Hackers Teamed Up to Attack Government and Corporate Infrastructure Cyber Security News
Printer Company Offered Malicious Drivers Infected With XRed Malware Printer Company Offered Malicious Drivers Infected With XRed Malware Cyber Security News
Windows LPE Vulnerabilities via Kernel Drivers and Named Pipes Allows Privilege Escalation Windows LPE Vulnerabilities via Kernel Drivers and Named Pipes Allows Privilege Escalation Cyber Security News
Critical Roundcube XSS Flaws Require Immediate Update Critical Roundcube XSS Flaws Require Immediate Update Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark