logo

This Android vulnerability can break your lock screen in under 60 seconds

ID: 4662a643-8b73-584c-a54d-4659635036c0

STIX ID: report--4662a643-8b73-584c-a54d-4659635036c0

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

...
...

A critical vulnerability (CVE-2026-20435) in MediaTek system-on-a-chip devices using Trustonic's Trusted Execution Environment allows an attacker with physical USB access to extract root keys before Android boots, recover the handset PIN, decrypt full-disk storage, and extract wallet seed phrases; researchers demonstrated the exploit, MediaTek published a firmware patch, and users are advised to install vendor updates or otherwise protect devices from loss or theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.