CVE-2026-20435Disclosure(google / android)

LOWCVSS 4.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.

3.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • mt2737
  • mt6739
  • mt6761

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 25 mentions across 12 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 15 signals
  • Disclosure: 16 classified signals
  • General: 5 classified signals
  • Peaked 8d ago at 5 mentions (2026-03-13); latest day: 1
  • 25 total mentions across 12 days

Affected systems

Products
androidmt2737mt6739mt6761mt6765mt6768mt6781mt6789mt6813mt6833

10 versions affected across 40 products

Deep dive

Activity timeline25 mentions / 12d
01345Mentions · 2026-03-02: 3Mentions · 2026-03-11: 1Mentions · 2026-03-12: 4Mentions · 2026-03-13: 5Mentions · 2026-03-14: 3Mentions · 2026-03-16: 3Mentions · 2026-03-25: 1Mentions · 2026-04-03: 1Mentions · 2026-04-05: 1Mentions · 2026-04-07: 1Mentions · 2026-04-25: 1Mentions · 2026-04-30: 1Exploit Tool / Code · 2026-03-14: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-03-02: 3Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 3Technical Details · 2026-03-16: 2Technical Details · 2026-03-25: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-07: 103-0203-1103-1203-1303-1403-1603-2504-0304-0504-0704-2504-30
Signal classification4 categories
Disclosure
1664.0%
General
520.0%
Patch
312.0%
False Positive
14.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-111
Patch1
2026-03-124
Disclosure3General1
2026-03-135
Disclosure1False Positive1General3
2026-03-143
Disclosure2Patch1
2026-03-163
Disclosure3
2026-03-251
Disclosure1
2026-04-031
General1
2026-04-051
Disclosure1
2026-04-071
Patch1
2026-04-251
Disclosure1
2026-04-301
Disclosure1
Full discourse20 posts
  • Ledger@Ledger
    False Positive

    The report circulating about "LDN-2026-0301" is false and based on manipulated screenshots. There is no such vulnerability in Ledger's transport layer, and no firmware update like the one described. The real research from the Ledger Donjon relates to CVE-2025-20435 (https://nvd.nist.gov/vuln/detail/CVE-2026-20435), a vulnerability affecting certain Android phones with MediaTek chips. In a compromised phone scenario, attackers may be able to extract data from software wallets. This highlights an important point: software wallets depend on the security of the phone they run on. If the phone is compromised, sensitive data can be exposed. Hardware wallets are designed to prevent this. Your private keys stay inside the secure element, and the only information you should trust is what appears on your Ledger's secure screen before signing. Ledger follows a zero-trust security model. Whether you connect to a phone or a computer, the device itself shows the final transaction details. If anything were changed by a malicious app or compromised system, it would appear on the device before you approve the transaction. A good reminder for everyone in crypto: screenshots and "reports" can be edited. What matters is what your device shows you before you sign. You can read the details of the real research from our CTO Charles Guillemet here: https://x.com/P3b7_/status/2031753534107001209

    Post summary

    The post debunks the LDN-2026-0301 claim as false while noting the real CVE-2025-20435 that can expose wallet data on Android phones.

    5141151129.3K
    669.8K followersView on X
  • أخبار التقنية 🌍@smartechdaily
    Disclosure

    🔐 ثغرة خطيرة في معالجات MediaTek 🚨 باحثون تمكنوا من اختراق هاتف Nothing CMF Phone 1 خلال 45 ثانية فقط عبر ثغرة تحمل الرمز CVE-2026-20435، ما يسمح باستخراج PIN وفك تشفير التخزين وحتى سرقة مفاتيح محافظ crypto دون تشغيل Android. الشركة أرسلت إصلاحًا للمصنّعين في Jan 2026، لكن ملايين الأجهزة قد تتأثر حتى يصل التحديث.

    Post summary

    Researchers identified CVE-2026-20435 in MediaTek processors, demonstrating extraction of PINs, decryption of storage, and theft of crypto keys on a Nothing CMF Phone 1 in under 45 seconds, and a patch will be released in January 2026.

    56071149.7K
    98.5K followersView on X
  • Charles Guillemet@P3b7_
    Patch

    As always, the Ledger Donjon followed a strict responsible disclosure process with the relevant vendors, which allowed security fixes to be released. MediaTek confirmed providing a fix to OEMs on Jan 5, 2026. The vulnerability is now public (CVE-2025-20435) https://nvd.nist.gov/vuln/detail/CVE-2026-20435

    Post summary

    The advisory confirms a patch release for CVE-2025-20435 after responsible disclosure, with no PoC, exploit, or active exploitation claims.

    4404965.3K
    42.4K followersView on X
  • Rand@randhindi
    General

    SGX Global Wrapping Key Extraction •TDXRay •Phoenix •CVE-2026-20435 •DNN Latency Sequencing (DLS) •Google-Intel TDX Audit •PMPlease •StackWarp •http://TEE.Fail •WireTap •Battering RAM •RMPocalypse •Heracles •VMScape •Relocate-Vote •Sigy •AMD-SB-3014 •CVE-2025-46733 •Cohere+Reload •Stack Engine Side Channel •CVE-2025-22889 •Defeating AutoLock •CounterSEVeillance •AMD Microcode Signature Bypass •SLAP & FLOP •BadRAM •TDXdown •HyperTheft •Qualcomm DSP 0-day •Microsoft/Intel TDX 1.5 Joint Security Review •Sinkclose •SGX Fuse Key Extraction •CacheWarp •Indirector •PowSpectre •TikTag •Pathfinder •WeSee •Heckler •GoFetch •ZenHammer •Faults in Our Bus

    Post summary

    The text lists a series of CVE identifiers and related vulnerability topics but lacks any evidence of PoC, detailed exploit code, or active exploitation, offering primarily a technical overview without actionable guidance.

    3002011.5K
    40.7K followersView on X
  • XdRiP Digital Management LLC@XDRIP
    Disclosure

    CVE-2026-20435 - a MediaTek chip flaw disclosed yesterday - allows wallet key extraction from roughly 25% of Android phones. Physical access. 45 seconds. The vulnerability sits below the OS. Software patches cannot fully address it. This is exactly the class of threat that XColdPro was designed to eliminate. Air-gapped machine. No network exposure. No consumer firmware dependency. No persistent key storage on disk. http://rc.xcoldpro.com

    Post summary

    CVE-2026-20435 is a MediaTek chip flaw disclosed yesterday that allows wallet key extraction from roughly 25% of Android phones when physical access is available, with no patch fully mitigating it; XColdPro is cited as a mitigation tool.

    0405075
    374 followersView on X
  • Brad Messier@KryptoBeard13
    Disclosure

    CVE-2026-20435 dropped yesterday. MediaTek chip vulnerability. Physical access to an Android phone — 45 seconds — wallet keys extracted. Affects roughly 25% of Android devices on the market. That is not a fringe scenario. That is someone picking up your phone at a bar. A border checkpoint. A repair shop. People carry their entire financial lives on these devices. And the silicon underneath is exposing them in ways they cannot see or prevent with software patches alone. This is why air-gapping matters. Not as a preference. As a requirement. If the machine holding your keys is network-connected and running consumer firmware, the question is not if it gets compromised. It is when. http://rc.xcoldpro.com

    Post summary

    The post announces the discovery of a MediaTek chip vulnerability (CVE‑2026‑20435), detailing its impact on a large portion of Android devices, but provides no PoC, exploit code, or evidence of active exploitation.

    0104065
    285 followersView on X
  • SempreUpdate@SempreUpdate
    Disclosure

    Falha nos chips MediaTek expõe PIN e dados em celulares Android https://sempreupdate.com.br/falha-chips-mediatek-cve-2026-20435-android/

    Post summary

    An article announces the discovery of CVE‑2026‑20435, a flaw in MediaTek chips that can expose PINs and data on Android phones, with no evidence provided of exploitation or remediation.

    0103064
    4.7K followersView on X
  • Network Services Group@NSGHELP
    Disclosure

    A critical vulnerability, tracked as CVE-2026-20435, is affecting up to 875 million Android phones powered by MediaTek chips. The flaw exists in the devices early boot process, raising serious questions about how... https://www.netservicesgroup.com/blog/a-hidden-android-flaw-that-breaks-the-lock-screen-in-seconds/

    Post summary

    The post announces CVE-2026-20435, noting its widespread impact on MediaTek-powered Android phones, but offers limited technical or remedial information.

    1001032
    45 followersView on X
  • #شيء_تك@ShaayTech
    Disclosure

    يواجه مستخدمو نظام Android تهديداً أمنياً خطيراً بعد اكتشاف ثغرة برمجية تتيح تجاوز قفل الشاشة والوصول إلى البيانات الشخصية. وكشف باحثون عن الخلل CVE-2026-20435 الذي يستهدف أجهزة تعمل بمعالجات MediaTek. وأوضحت شركة Malwarebytes المتخصصة في الأمن السيبراني، أن المشكلة ترتبط ببيئة التنفيذ الموثوقة التابعة لشركة Trustonic، ويمكن استغلالها خلال نحو 60 ثانية عبر USB، مما يهدد ملايين الأجهزة، خاصة مع تأخر التحديثات الأمنية لدى الشركات المصنعة.

    Post summary

    Researchers disclosed CVE-2026-20435, a flaw in Android devices using MediaTek chips that can bypass screen lock via the Trusted Execution Environment over USB in about 60 seconds, affecting millions of devices.

    01010213
    167.4K followersView on X
  • まっきーの@makino_615
    Disclosure

    CVE-2026-20435 影響を受けるチップ MT2737、MT6739、MT6761、MT6765、MT6768、MT6781、MT6789、MT6813、MT6833、MT6853、MT6855、MT6877、MT6878、 MT6879、MT6880、MT6885、MT6886、MT6890、MT6893、MT6895、MT6897、MT6983、MT6985、MT6989、MT6990、MT6993、 MT8169、MT8186、MT8188、MT8370、

    Post summary

    The entry announces that CVE-2026-20435 affects a list of MT530 series chips, serving as a straightforward disclosure without additional technical, exploit, or mitigation details.

    1010093
    96 followersView on X
  • Grok@grok
    Patch

    نعم، الثغرة CVE-2026-20435 تؤثر على شرائح ميدياتك محددة (مثل MT6739، MT6765، MT6895، وغيرها - القائمة الكاملة في نشرة أمان ميدياتك مارس 2026). لا توجد قائمة رسمية بكل موديلات الهواتف، لكن تحقق من معالج هاتفك (SoC) عبر إعدادات > عن الهاتف أو GSMArena، ثم قارنه بالقائمة. تحديث النظام الأمني الأخير من الشركة المصنعة يكفي تماماً لسد الثغرة، حيث أصدرت ميدياتك التصحيح للشركات المصنعة منذ يناير. لا يحتاج الأمر تدخلاً أعمق.

    Post summary

    The post announces that CVE-2026-20435 impacts specific MediaTek SoCs and confirms that the latest vendor patch fully mitigates the issue, with no active exploitation reported.

    0001096
    8.6M followersView on X
  • Peterwens Dourolph Denival@CyberTech_Actu
    Disclosure

    [Cyber/Alerte] Faille Android : Votre écran de verrouillage peut être contourné en 60 secondesUne vulnérabilité critique (CVE-2026-20435) a été découverte sur certains smartphones Android utilisant des puces MediaTek. Elle permet à un attaquant physique de contourner l'écran de verrouillage pour extraire le code PIN, les clés de chiffrement et même les phrases de récupération de portefeuilles crypto en moins d'une minute. Source : https://dcod.ch/2026/03/16/vulnerabilites-les-11-alertes-critiques-du-16-mar-2026/

    Post summary

    A new critical Android lock‑screen bypass (CVE‑2026‑20435) affecting MediaTek devices can extract PINs, encryption keys and crypto wallet recovery phrases in under a minute.

    0001051
    34 followersView on X
  • Laberinto Digital@ZamnaX_89
    Patch

    Tu PIN es irrelevante frente a un exploit de 60 segundos. La vulnerabilidad CVE-2026-20435 en chips MediaTek rompe la arquitectura de confianza de millones de dispositivos Android. Con solo una conexión USB, un atacante puede extraer llaves de cifrado, recuperar tu PIN y vaciar tus wallets antes de que el sistema termine de arrancar. No es un fallo de software; es una grieta en el corazón del hardware (TEE). El "muro" de tu pantalla de bloqueo es ahora de papel. Verifica tu SoC. Si tu fabricante ya no ofrece soporte (EOL), tu privacidad tiene fecha de caducidad. En el Laberinto, el parche no es una opción, es la única defensa. #Android #CyberSecurity #MediaTek #Exploit #Privacy #LaberintoDigital

    Post summary

    The post alerts users to a hardware vulnerability (CVE‑2026‑20435) on MediaTek chips that can expose encryption keys and pins via USB; it stresses that no patch is currently available, urging verification of device support.

    0001064
    7 followersView on X
  • 情報弱者であると同時に、情感弱者@joukan_jakusha
    Disclosure

    MediaTekのSoCの脆弱性(CVE-2026-20435)、対象すごい多いな。 https://t.co/j3U6OfBZHZ

    Post summary

    The tweet announces the discovery of CVE-2026-20435 affecting many MediaTek SoC devices, but provides no further technical or mitigation details.

    10000172
    415 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20435 Local Information Disclosure in Preloader via Device Unique Identifier Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20435

    Post summary

    The text announces CVE-2026-20435, describing a local information disclosure vulnerability in Preloader via device unique identifier access, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0001048
    4.0K followersView on X
  • Ayacht Tech Solution@ayachttechsltns
    Disclosure

    The Android security gap that starts before your phone turns on: A newly disclosed security flaw, CVE-2026-20435, is putting as many as 875 million Android phones at risk. Found in devices using… http://dlvr.it/TSCnxF #Android #2026april24android_c #android #cybersecurity https://t.co/fnCVG8fUex

    Post summary

    A new Android vulnerability, CVE-2026-20435, has been announced and may affect up to 875 million devices, though detailed technical data and remediation steps are not provided.

    0000052
    33 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical Android bug CVE-2026-20435 lets attackers with USB access unlock some MediaTek phones in under 60 seconds, exposing encrypted data and crypto wallets. https://threatcluster.io/cluster/critical-android-vulnerability-allows-quick-unlocking-of-dev-ebebe15e

    Post summary

    A new critical Android vulnerability (CVE‑2026‑20435) allows attackers to unlock certain MediaTek phones via USB in under a minute, potentially exposing encrypted data and crypto wallets. No active exploitation, patch, or PoC details are provided yet.

    0000048
    124 followersView on X
  • のら@nora_nya
    General

    ていうか、ウチの ALLDOCUBE iPlay 60 mini Pro NFEも cve-2026-20435 の脆弱性対象なんじゃないか? ヤバいな、、、

    Post summary

    The user speculates that their ALLDOCUBE iPlay 60 mini Pro NFE may be affected by CVE-2026-20435, but provides no additional technical detail.

    00000152
    103 followersView on X
  • Emerson Yougbaré@emzrsxn
    General

    https://nvd.nist.gov/vuln/detail/CVE-2026-20435

    Post summary

    The provided text is a link to an NVD CVE page without explicit details about exploitation, patching, or technical specifics.

    0000037
    1.6K followersView on X
  • rebus@therebus
    Disclosure

    "This Android vulnerability can break your lock screen in under 60 seconds" A vulnerability in Android devices can allow attackers to gain access to a phone in less than a minute. The vulnerability, tracked as CVE-2026-20435, affects certain MediaTek S… https://ift.tt/Lh6wFGy

    Post summary

    The text announces CVE-2026-20435, highlighting its ability to break Android lock screens in under a minute, but offers no further technical details, mitigation advice, or evidence of active exploitation.

    0000062
    1.1K followersView on X
CPE platform detail44 entries

44 of 44 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--
Applinuxfoundationyocto4.0--
HWmediatekmt2737---
HWmediatekmt6739---
HWmediatekmt6761---
HWmediatekmt6765---
HWmediatekmt6768---
HWmediatekmt6781---
HWmediatekmt6789---
HWmediatekmt6813---
HWmediatekmt6833---
HWmediatekmt6853---
HWmediatekmt6855---
HWmediatekmt6877---
HWmediatekmt6878---
HWmediatekmt6879---
HWmediatekmt6880---
HWmediatekmt6885---
HWmediatekmt6886---
HWmediatekmt6890---
HWmediatekmt6893---
HWmediatekmt6895---
HWmediatekmt6897---
HWmediatekmt6983---
HWmediatekmt6985---
HWmediatekmt6989---
HWmediatekmt6990---
HWmediatekmt6993---
HWmediatekmt8169---
HWmediatekmt8186---
HWmediatekmt8188---
HWmediatekmt8370---
HWmediatekmt8390---
HWmediatekmt8676---
HWmediatekmt8678---
HWmediatekmt8696---
HWmediatekmt8793---
OSopenwrtopenwrt21.02.0--
OSopenwrtopenwrt23.05.0--
Apprdkcentralrdk-b2022q3--
Apprdkcentralrdk-b2024q1--
OSzephyrprojectzephyr3.7.0--

Explore more