CVE-2026-20435
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-20435 is a logic error vulnerability in the MediaTek preloader component that allows a physically present attacker to read device unique identifiers without any privileges or user interaction. It affects Android 14.0, 15.0, and 16.0 on a wide range of MediaTek chipsets (including MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6813, MT6833, MT6853, MT6855, MT6877, MT6878, MT6879, MT6885, MT6886, MT6893, MT6895, MT6897, MT6983, MT6985, MT6989, MT6990, MT6993, and others), as well as OpenWRT 21.02/23.05, Yocto 4.0, RDK-B 22Q3/24Q1, and Zephyr 3.7.0. The vulnerability was published on March 2, 2026, with a patch released in MediaTek's March 2026 Product Security Bulletin and included in the Android June 2026 security update. It carries a CVSS v3.1 base score of 4.6 (Medium) (MediaTek Bulletin, Android Bulletin).

Technical details

The vulnerability is rooted in a logic error within the MediaTek preloader — the early-stage bootloader component responsible for initializing hardware before the main OS loads — classified as CWE-522 (Insufficiently Protected Credentials). Due to this logic flaw, device unique identifiers (such as hardware-bound identifiers used for device attestation or encryption) can be read without authentication or elevated privileges. The attack vector is physical (AV:P), meaning an attacker must have hands-on access to the device; no software-based remote exploitation path exists. Patch ID ALPS10607099 addresses the issue (Issue ID: MSV-6118) (MediaTek Bulletin). Media coverage has described the practical impact as enabling lock screen bypass in under 60 seconds on affected devices, though no formal public PoC code has been confirmed (Malwarebytes).

Impact

Successful exploitation results in local information disclosure — specifically, the unauthorized reading of device unique identifiers from the preloader. These identifiers can potentially be leveraged to bypass device authentication mechanisms (e.g., lock screen PINs), clone device credentials, or undermine hardware-backed security features such as encrypted storage or crypto wallet protections. The confidentiality impact is rated High, while integrity and availability are unaffected. The scope is limited to the physical device; no network-based lateral movement is possible from this vulnerability alone (MediaTek Bulletin, Android Headlines).

Exploitability

No confirmed public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.021%, reflecting a low probability of near-term automated exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires physical access to the device, significantly limiting the attacker pool. The vulnerability has been detected by Qualys (detection ID: 610785) and has attracted broad media attention, with headlines describing potential lock screen bypass in under 60 seconds on affected MediaTek-powered Android devices (Malwarebytes, Android Authority).

Exploitation steps

  1. Physical Access: Obtain physical access to a target Android device running a MediaTek chipset listed in the advisory (e.g., MT6761, MT6765, MT6833, MT6877, etc.) on Android 14, 15, or 16 without the June 2026 security patch applied.
  2. Boot into Preloader Mode: Force the device into preloader/download mode (typically by holding a hardware button combination during power-on), which exposes the preloader interface.
  3. Interface with Preloader: Connect the device to a computer via USB and use a MediaTek-compatible flashing or diagnostic tool (e.g., SP Flash Tool or a custom utility) to communicate with the preloader.
  4. Exploit Logic Error: Send crafted commands that trigger the logic error in the preloader, causing it to return device unique identifiers (e.g., hardware-bound device IDs) without enforcing access controls.
  5. Extract Identifiers: Capture the returned unique identifiers, which can then be used to derive encryption keys, bypass lock screen authentication, or clone device credentials for further attacks (MediaTek Bulletin, Malwarebytes).

Indicators of compromise

  • Physical: Evidence of device having been connected to an unknown USB host while powered off or in recovery/download mode; unexpected wear or marks on USB port.
  • Logs: Android system logs (logcat) showing unexpected preloader or bootloader interactions; entries indicating device entered download mode outside of normal update procedures.
  • Device State: Device lock screen PIN/password unexpectedly bypassed or changed; device showing signs of re-enrollment or factory reset without user initiation.
  • File System: Presence of unfamiliar diagnostic or flashing tools on a connected computer (e.g., SP Flash Tool, MTK client utilities) that may have been used to interface with the preloader.

Mitigation and workarounds

MediaTek released a patch (Patch ID: ALPS10607099) in the March 2026 Product Security Bulletin, and the fix is included in the Android June 2026 security update (patch level 2026-06-01). Device manufacturers including Samsung have incorporated the patch in their April and June 2026 security updates. Users should apply the latest available security patch for their device as the primary remediation. As a workaround, organizations should restrict physical access to devices containing sensitive data, enforce device management policies that detect unauthorized boot mode access, and consider enabling full-disk encryption to limit the utility of extracted identifiers (MediaTek Bulletin, Android Bulletin, SammyFans June).

Community reactions

The vulnerability attracted significant media attention, with outlets including Malwarebytes, Android Authority, Fox News, GB News, and the Mirror publishing articles describing the flaw as enabling lock screen bypass in under 60 seconds (Malwarebytes, Android Authority). Community discussion on Reddit (r/NOTHING and r/NothingTech) highlighted concern among users of Nothing Phone devices, which use MediaTek chipsets (Reddit NOTHING). A dev.to post framed the vulnerability as exposing crypto wallets on approximately 25% of Android phones, though this characterization appears speculative beyond the official advisory scope. MediaTek and Google have not issued public statements beyond their standard security bulletins.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management