Android March security update will fully fix MediaTek-SU permission vulnerability

Android March security update will fully fix MediaTek-SU permission vulnerability

Google today reiterated the importance of keeping Android smartphones up to date with security updates, and users of devices based on MediaTek chips should be more vigilant. In its March 2020 security bulletin, it pointed out a year-old CVE-2020-0069 security vulnerability. XDA-Developers wrote in a report this week that they had known about it as early as April 2019.

Some apps in the Play Store that abuse the MediaTek-SU vulnerability (Image from: TrendMicro)

Similar to the vulnerability disclosed by Google in CVE-2020-0069, the XDA-Developers forum calls it MediaTek-SU, and the suffix indicates that malicious programs can use it to gain super user access.

By exploiting the MediaTek-SU security vulnerability, malicious programs can obtain almost complete functional permissions and even edit and modify related content at will without first obtaining root permissions of the device (processing the bootloader).

For malware authors, this is tantamount to opening a backdoor panel on Android phones, allowing them to do whatever they want to users.

From the moment he gains privileged access, he can get his hands on any data, input, and content coming in and out. The app can even execute malicious code in the background, sending commands to the device without the user's knowledge.

MediaTek quickly discovered the vulnerability and released a fix, but unfortunately, device manufacturers don’t have much incentive to push security updates to users. A year later, many users are still exposed to the risk.

The good news is that MediaTek and Google have now reached a closer collaboration to integrate this fix into the Android standard security update patch in March. After the manufacturer pushes the OTA update, please install and deploy it in time to eliminate this security risk.

<<:  The differences between Android and iOS are getting smaller and smaller, but the latter does not do as well in security and other features

>>:  Huawei HMS will cooperate with India's Indus OS to replace Google GMS with 400,000 APP applications

Recommend

WeChat Reading Product Analysis Report

" WeChat Reading " is a reading softwar...

How to systematically design online and offline brand activities?

Different from daily operational activities, offl...

The sixth session of the Aiti Tribe Technical Clinic

【51CTO.com original article】 [51CTO original arti...

Product Operation: Analyzing the group buying model and advanced gameplay!

The popularity of group buying probably started i...

The most effective App promotion channels, a summary of strengths!

What are the most effective App promotion channel...

How to write efficient Android code

As Android-related devices are embedded devices, ...

Video promotion tips: Revealing the new algorithm recommended by the platform!

With the development of 5G and 4K/8K HDTV technol...

Community operation: 5 elements and 7 key points of high-quality communities!

Social media has the advantages of low cost and h...

How to learn from the "toxic" Thai advertisements?

Whether you are in the advertising industry or no...

Xiaohongshu promotion strategy: Xiaohongshu live broadcast internal testing!

According to Xiaohongshu influencers, Xiaohongshu...

Toutiao officially launches CPA (cost-per-acquisition) model

The conversion cost is sometimes high and sometim...