Skip to main content

A flaw in MediaTek audio chips could have exposed Android users’ conversations

Security researchers have discovered a new flaw in a MediaTek chip used in over a third of the world’s smartphones that could have potentially been used to listen in on private conversations. The chip in question is an audio processing chip by MediaTek that’s found in many Android smartphones from vendors such as Xiaomi, Oppo, Realme, and Vivo. Left unpatched, researchers say, a hacker could have exploited the vulnerabilities in the chip to eavesdrop on Android users and even hide malicious code.

Check Point Research (CPR) reverse-engineered MediaTek’s audio chip, discovering an opening that could allow a malicious app to install code meant to intercept audio passing through the chip and either record it locally or upload it to an attacker’s server. 

CPR disclosed its findings to MediaTek and Xiaomi several weeks ago, and the four identified vulnerabilities have already been patched by MediaTek. Details on the first can be found in MediaTek’s October 2021 Security Bulletin, while information on the fourth will be published in December. 

“MediaTek is known to be the most popular chip for mobile devices,” Slava Makkaveev, Security Researcher at Check Point Software, said to Digital Trends in a press release. “Given its ubiquity in the world, we began to suspect that it could be used as an attack vector by potential hackers. We embarked research into the technology, which led to the discovery of a chain of vulnerabilities that potentially could be used to reach and attack the audio processor of the chip from an Android application.”

Fortunately, it looks like researchers caught the flaws before they could be exploited by malicious hackers. Makkaveev also raised concerns about the possibility of device manufacturers exploiting this flaw “to create a massive eavesdrop campaign;” however, he notes that his firm didn’t find any evidence of such misuse. 

Tiger Hsu, product security officer at MediaTek, also said that the company has no evidence that the vulnerability has been exploited but added that it worked quickly to verify the problem and make the necessary patches available to all device manufacturers who rely on MediaTek’s audio processors. 

Flaws like these are also often mitigated by security features in the Android operating system and the Google Play Store, and both Makkaveev and Hsu are reminding users to keep their devices updated to the latest available security patches and only install applications from trusted locations. 

Editors' Recommendations

Jesse Hollington
Jesse has been a technology enthusiast for his entire life — he probably would have been born with an iPhone in his hand…
OnePlus Nord 2 will use a customized version of MediaTek’s flagship chip
OnePlus 9 Pro's camera module in close up.

The OnePlus Nord 2 5G is now officially coming soon, and it will be the first OnePlus phone to feature a MediaTek processor and not a Qualcomm chip. The Nord 2 will use MediaTek’s flagship, top-spec Dimensity 1200 chip, which will be customized under the Dimensity Open Resource Architecture initiative, where device makers can tune the processor to its own requirements.

Rumors about a MediaTek-powered Nord 2 have spread for a while, and while this announcement has made the partnership and device name official, there’s no indication when the phone will get a full launch, or its other specifications. Instead, it concentrates on how MediaTek and OnePlus have customized the Dimensity 1200.

Read more
The Poco M3 Pro 5G is the latest low-cost 5G phone to use the MediaTek 700 chip
poco m3 pro 5g news colors

Poco Global, the smartphone company best known for high-performance, low-cost phones like the Poco F1 and Poco F2 Pro, has announced the Poco M3 Pro 5G. The new phone is the latest in a growing trend of cheap 5G phones, made possible by using competitively priced processors like the MediaTek Dimensity 700, which powers the Poco M3 Pro 5G and the recently announced Realme 8 5G.

It’s the first time Poco has worked with MediaTek, which is working hard to increase its influence in 5G. The Dimensity 700 is a 2.2GHz octa-core chip built using a 7mn process, and although not MediaTek’s flagship 5G chip, is still designed to cope with games, video, and other power-intensive activities. In the M3 Pro 5G, it’s paired to either 4GB or 6GB of RAM, which come with 64GB or 128GB of storage space respectively.

Read more
MediaTek’s Dimensity 1200 mobile chip handles cameras with up to 200 megapixels
mediatek dimensity 1200 1100 processor news chip

MediaTek has announced two new additions to its 5G mobile processor range, the Dimensity 1200 and the Dimensity 1100, which though an impressive series of spec upgrades, may help the company’s chips find their way into more high-end smartphones very soon. MediaTek powers many smart home products, from Amazon’s Echo hardware to the majority of smart TVs available, and a growing number of capable smartphones, but is not as well known as Qualcomm in the world of high-end flagship mobile hardware.

The Dimensity 1200 could change that. Built using a 6nm process, the octa-core Dimensity 1200 uses an ultra-core Arm Cortex A78, three super-core Arm Cortex A78, and four Arm Cortex A55 cores, with a Sub-6 5G modem built-in, a nine-core GPU, and an updated six-core APU for artificial intelligence duties which provides a 10% performance upgrade over previous versions.

Read more