An urgent security alert has been issued for Android users regarding a critical vulnerability that could potentially allow cybercriminals to bypass a phone’s lock screen. The flaw, identified by the Donjon security team, poses a significant risk as attackers could exploit it within a minute, gaining access to sensitive data stored on the device.
Researchers demonstrated the exploit by connecting a vulnerable Android device to a laptop via USB, revealing that they were able to retrieve the device’s PIN, decrypt storage, and access confidential files, including data from software wallets, all in under 60 seconds.
The vulnerability, known as CVE-2026-20435, primarily affects Android devices powered by MediaTek processors, which are commonly found in budget-friendly smartphones, putting a substantial number of devices at risk.
Security experts have warned that the flaw enables attackers to extract encryption keys before the system fully boots, circumventing security measures like full-disk encryption and lock screen protections.
Malwarebytes, a cybersecurity firm, emphasized the severity of the vulnerability, highlighting that it impacts MediaTek SoCs utilizing Trustonic’s TEE, potentially affecting about one in four Android phones, particularly lower-priced models.
To mitigate the risk, users are advised to check their device’s processor information in the Settings menu and promptly install any available security updates, especially if their phone runs on a MediaTek chip. MediaTek has already released a patch for the vulnerability, but it is essential for individual device manufacturers to distribute the fix through software updates for comprehensive protection.
It is crucial to note that the attack requires physical access to the device. By ensuring that phones are regularly updated and remain in the user’s possession, the risk of exploitation is significantly reduced. However, users with older devices that no longer receive updates are encouraged to exercise caution or consider upgrading to mitigate potential security threats.
