Your MediaTek-powered Android devices may be at risk

amazon-fire-hd-10-2017-3.jpg?itok=CA9nLe

Android devices from Amazon, Nokia, LG and more are affected and need the March 2020 security patch or a fix from the device-maker itself.

MediaTek makes chips that power millions of devices. Some you’ve heard of, like the Amazon Fire HD tablet(s), others, like the Alcatel Tetra, you probably haven’t. Almost all of them have something in common though: a bug in the CPU firmware that allows a simple script “root” the device itself.

This was first found by developers at XDA Forums, and almost every single 64-bit MediaTek CPU is vulnerable unless it’s been patched. And some devices are patched since a recent update but the list isn’t very long:

  • Samsung has patched its phones
  • Vivo has patched its phones
  • Huawei and Honor phones with Android 8 or higher have been patched
  • Oppo phones with Android 8 or higher have been patched
  • Phones running Android 10 are immune
  • Amazon Fire HD tablets may be patched if they have a specific firmware version.

That leaves a whole lot of unpatched devices with a critical exploit in the system that should have been wiped out a long time ago, as MediaTek released a firmware patch in May 2019 to developers who use the affected chipsets.

The dirty details of the whole thing are a really interesting read, even if you’re not “into” Android security. This was originally discovered by XDA developer diplomatic as an easy way to root the Amazon Fire HD tablets, and things progressed from there. Eventually, Google was forced to get involved and worked with the XDA team to release the details in conjunction with a complete system-wide fix for any phone maker that’s included as part of the March 2020 Android Security Bulletin.

MediaTek’s Helio P95 chipset is here with minor AI and camera tweaks

Many of us aren’t going to be affected because we don’t use any MediaTek-powered devices, but word-wide we’re talking about millions and millions of phones, tablets, and Android-powered set-top boxes. It’s a pretty big deal. That doesn’t mean that it’s going to get fixed in any sort of timely or meaningful way, though.

For all the work MediaTek, XDA developers, and Google have done to matter the company which made your device has to send out an update. Let’s be frank here: looking at the list of affected devices (which you can find at Mishaal Rahman’s excellent write-up) it’s obvious that many will never see this patch. That means it’s up to the owners of these devices to be proactive.

  • Only download applications from official app storefronts like Google Play or Amazon’s App Store.
  • Read reviews of apps before you install them.
  • Pay attention to all the permissions an app requests and if anything seems fishy, just say no.
  • Remember that the company who made your device left you high and dry when you make your next purchase.

We want everyone’s experience to be awesome when they use their phone or tablet. And even though there’s a particularly nasty bug in some of them, and it may never be fixed, you still can. Just take a bit of extra time before you install any applications and you can be safe.

Amazon Fire HD 10

Best Amazon tablet

amazon-fire-hd-10-colors-official-render

One of the best media consumption devices you can buy under $200.

From $150 at Amazon $150 at Best Buy

If you plan on watching a lot of movies on your tablet, the Fire HD 10 is the clear winner. Its display is larger and higher density than the HD 8, it comes with more onboard storage, and the speakers are louder and clearer.

Latest posts

Siri won’t be your AI girlfriend

‘Listen, that's not what I'm here for, right?' | Image: Apple Our early testing has already shown that Siri AI knows when to shut up,...

Amazon’s Echo Hub gets a customizable new look and Ring’s AI features

Amazon's rolling out a free software update for Echo Hub devices that gives the home screen a much-needed update to the interface it launched...

Telegram brings back its Wear OS app after five years with chats, voice messages, more

Five years after killing its Wear OS app, Telegram is reviving support for Android smartwatches with its latest update. Read more @ 9to5google

Waze now shows traffic lights on your route, but it’s rolling out slowly

In testing for several months now, Waze is starting to roll out traffic lights more widely in navigation, but it’s still not available to...

Here are the price-matching policies for Best Buy, GameStop, and others

Nothing is more frustrating than buying a new pair of headphones, an OLED TV, or a laptop just to find out that you could...

The bill that would let Jimmy Kimmel sue Brendan Carr is here

Under a new bipartisan bill, Americans could sue for damages if a government official illegally tries to coerce a social media, AI, or broadcasting...

Amazon’s data centers used 2.5 billion gallons of water last year

Just after Seattle enacted a one-year data center moratorium that some of Amazon's own employees pushed for, Amazon shared how much water its data...

Roborock’s Q10 S5 Plus robovac is over half off, matching its best price to date

Roborock’s Q10 S5 Plus comes with a self-emptying dock and is under $300. | Image: Roborock Even at full price, the Roborock Q10 S5 Plus...

Blink’s six-piece outdoor camera kit is a great deal under $200

You can save on a big set of outdoor security cameras ahead of Prime Day. Amazon has a five-pack of Blink cameras with a...

Logitech’s awesome MX Master 3S mouse drops to under $100

The platform-agnostic Logitech MX Master 3S wireless mouse is discounted to $89.99 at Amazon ($30 off), matching the best price we’ve seen so far...