CVE-2025-20435Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-12); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-11: 1Mentions · 2026-03-12: 3Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 103-1103-1203-1303-1603-17
Signal classification4 categories
Patch
228.6%
Disclosure
228.6%
General
228.6%
False Positive
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-111
Patch1
2026-03-123
Disclosure2General1
2026-03-131
False Positive1
2026-03-161
Patch1
2026-03-171
General1
Full discourse7 posts
  • Ledger@Ledger
    False Positive

    The report circulating about "LDN-2026-0301" is false and based on manipulated screenshots. There is no such vulnerability in Ledger's transport layer, and no firmware update like the one described. The real research from the Ledger Donjon relates to CVE-2025-20435 (https://nvd.nist.gov/vuln/detail/CVE-2026-20435), a vulnerability affecting certain Android phones with MediaTek chips. In a compromised phone scenario, attackers may be able to extract data from software wallets. This highlights an important point: software wallets depend on the security of the phone they run on. If the phone is compromised, sensitive data can be exposed. Hardware wallets are designed to prevent this. Your private keys stay inside the secure element, and the only information you should trust is what appears on your Ledger's secure screen before signing. Ledger follows a zero-trust security model. Whether you connect to a phone or a computer, the device itself shows the final transaction details. If anything were changed by a malicious app or compromised system, it would appear on the device before you approve the transaction. A good reminder for everyone in crypto: screenshots and "reports" can be edited. What matters is what your device shows you before you sign. You can read the details of the real research from our CTO Charles Guillemet here: https://x.com/P3b7_/status/2031753534107001209

    Post summary

    The post refutes the alleged LDN‑2026‑0301 Ledger vulnerability, confirms no firmware update is needed, and clarifies that the real issue is CVE‑2025‑20435 affecting Android phones with MediaTek chips, highlighting the security benefits of Ledger hardware wallets.

    5141151129.3K
    669.8K followersView on X
  • Charles Guillemet@P3b7_
    Patch

    As always, the Ledger Donjon followed a strict responsible disclosure process with the relevant vendors, which allowed security fixes to be released. MediaTek confirmed providing a fix to OEMs on Jan 5, 2026. The vulnerability is now public (CVE-2025-20435) https://nvd.nist.gov/vuln/detail/CVE-2026-20435

    Post summary

    The post reports that a vendor confirmed a patch for CVE-2025-20435, following responsible disclosure, with no additional technical details or PoC revealed.

    4404965.3K
    42.4K followersView on X
  • ✨_geeknik_//✨@geeknik
    Patch

    Your phone's "off" switch was never a lock. CVE-2025-20435: 875M Android devices. USB in. 60 seconds. PIN cracked, encryption stripped, before the OS even blinks. Check your MediaTek chip. Patch now. Or hand-deliver your secrets. https://www.forbes.com/sites/daveywinder/2026/03/15/critical-flaw-875-million-android-phones-at-risk-of-60-second-hack/?streamIndex=0

    Post summary

    The post warns that CVE‑2025‑20435 allows attackers to extract PINs and encryption from 875 million Android devices via USB in ~60 seconds, and urges users to patch MediaTek chips immediately.

    02011287
    20.3K followersView on X
  • Dr. Binary@drbinaryai
    General

    Good writeup. For Android CVEs, what helps teams most is mapping which builds are exposed version + build date + vendor patch level, not just the CVE text. Https://drbinary.ai can take an Android version/build time and list affected CVEs quickly handy for triage. Does CVE-2025-20435 hinge on a specific component/permission boundaryd

    Post summary

    The post briefly mentions CVE-2025-20435 without providing any technical details, exploitation information, patches, or PoC evidence, hence it falls under general reporting.

    1000050
    254 followersView on X
  • CCN@CCNCitizens
    Disclosure

    🚨 New Android Security Alert A flaw in MediaTek chips (CVE-2025-20435) could let attackers steal your crypto in under 45 seconds. 🔑 What you should know: • No malware, internet, or password needed • Physical access + USB cable is enough • Attack can extract PINs & seed phrases from popular wallets • Affects many mid-range Android phones globally

    Post summary

    An Android security alert identifies a MediaTek chip flaw (CVE‑2025‑20435) that could allow attackers to extract wallet PINs and seed phrases via physical USB access; no PoC, exploit tool, patch, or active exploitation evidence is provided.

    10000467
    183.6K followersView on X
  • Kryptouutiset.net@Kryptouutiset1
    General

    Haavoittuvuus (CVE-2025-20435) koskettaa arviolta jopa 25 prosenttia Android-laitteista. Asiantuntijoiden mukaan älypuhelimia ei ole alun perinkään suunniteltu toimimaan digitaalisina kassakaappeina, mikä korostaa laitteistoriskien ymmärtämistä. 🧵 3/5

    Post summary

    The post notes that CVE-2025-20435 may affect up to 25% of Android devices, but offers no technical, exploit, or remediation details.

    1000095
    3.1K followersView on X
  • TheNewsCrypto@The_NewsCrypto
    Disclosure

    🚨 SECURITY ALERT: Ledger researchers expose a critical Android chip flaw targeting crypto wallets. Ledger’s Donjon team demonstrated a vulnerability (CVE-2025-20435) in MediaTek processors that could allow attackers with physical access to extract wallet seed phrases in about 45 seconds. Wallets tested include Trust Wallet, Kraken Wallet, and Phantom. #Crypto #Security #Android #Ledger

    Post summary

    Ledger researchers have identified and demonstrated a critical flaw (CVE-2025-20435) in MediaTek Android processors that lets an attacker with physical access extract crypto wallet seed phrases in roughly 45 seconds; no patch or exploit code has been released yet.

    00000142
    29.7K followersView on X

Explore more