
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20435 is a logic error vulnerability in the MediaTek preloader component that allows a physically present attacker to read device unique identifiers without any privileges or user interaction. It affects Android 14.0, 15.0, and 16.0 on a wide range of MediaTek chipsets (including MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6813, MT6833, MT6853, MT6855, MT6877, MT6878, MT6879, MT6885, MT6886, MT6893, MT6895, MT6897, MT6983, MT6985, MT6989, MT6990, MT6993, and others), as well as OpenWRT 21.02/23.05, Yocto 4.0, RDK-B 22Q3/24Q1, and Zephyr 3.7.0. The vulnerability was published on March 2, 2026, with a patch released in MediaTek's March 2026 Product Security Bulletin and included in the Android June 2026 security update. It carries a CVSS v3.1 base score of 4.6 (Medium) (MediaTek Bulletin, Android Bulletin).
The vulnerability is rooted in a logic error within the MediaTek preloader — the early-stage bootloader component responsible for initializing hardware before the main OS loads — classified as CWE-522 (Insufficiently Protected Credentials). Due to this logic flaw, device unique identifiers (such as hardware-bound identifiers used for device attestation or encryption) can be read without authentication or elevated privileges. The attack vector is physical (AV:P), meaning an attacker must have hands-on access to the device; no software-based remote exploitation path exists. Patch ID ALPS10607099 addresses the issue (Issue ID: MSV-6118) (MediaTek Bulletin). Media coverage has described the practical impact as enabling lock screen bypass in under 60 seconds on affected devices, though no formal public PoC code has been confirmed (Malwarebytes).
Successful exploitation results in local information disclosure — specifically, the unauthorized reading of device unique identifiers from the preloader. These identifiers can potentially be leveraged to bypass device authentication mechanisms (e.g., lock screen PINs), clone device credentials, or undermine hardware-backed security features such as encrypted storage or crypto wallet protections. The confidentiality impact is rated High, while integrity and availability are unaffected. The scope is limited to the physical device; no network-based lateral movement is possible from this vulnerability alone (MediaTek Bulletin, Android Headlines).
No confirmed public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.021%, reflecting a low probability of near-term automated exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires physical access to the device, significantly limiting the attacker pool. The vulnerability has been detected by Qualys (detection ID: 610785) and has attracted broad media attention, with headlines describing potential lock screen bypass in under 60 seconds on affected MediaTek-powered Android devices (Malwarebytes, Android Authority).
MediaTek released a patch (Patch ID: ALPS10607099) in the March 2026 Product Security Bulletin, and the fix is included in the Android June 2026 security update (patch level 2026-06-01). Device manufacturers including Samsung have incorporated the patch in their April and June 2026 security updates. Users should apply the latest available security patch for their device as the primary remediation. As a workaround, organizations should restrict physical access to devices containing sensitive data, enforce device management policies that detect unauthorized boot mode access, and consider enabling full-disk encryption to limit the utility of extracted identifiers (MediaTek Bulletin, Android Bulletin, SammyFans June).
The vulnerability attracted significant media attention, with outlets including Malwarebytes, Android Authority, Fox News, GB News, and the Mirror publishing articles describing the flaw as enabling lock screen bypass in under 60 seconds (Malwarebytes, Android Authority). Community discussion on Reddit (r/NOTHING and r/NothingTech) highlighted concern among users of Nothing Phone devices, which use MediaTek chipsets (Reddit NOTHING). A dev.to post framed the vulnerability as exposing crypto wallets on approximately 25% of Android phones, though this characterization appears speculative beyond the official advisory scope. MediaTek and Google have not issued public statements beyond their standard security bulletins.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."