Android security: Google patches a dangerous flaw in these phones
Google has disclosed a severe vulnerability affecting dozens of models of mid-range Android devices running on chips from MediaTek. Malicious Android apps have been exploiting the flaw since at least January 2020.
The elevation-of-privilege flaw, tracked as CVE-2020-0069, is disclosed in Google's March 2020 Android bulletin and affects the MediaTek Command Queue driver.
The dangerous part about this bug is that an exploit has been floating around for almost a year called 'MediaTek-su', which enables temporary root access on a large number of MediaTek chips.
A developer who goes by the name 'diplomatic' used XDA-Developers' forums to share a script that users can run to gain superuser (su) access.
While it was originally intended for rooting Amazon Fire devices to modify them, any app can incorporate MediaTek-su and execute it to gain root access in shell, according to XDA-Developers. However, a malicious app's root access won't survive a device reboot.
TrendMicro reported in January that several malicious apps available on Google Play were using MediaTek-su to gain root access on Android devices.
The apps were using the exploit to collect infected devices' location, battery status, files, a list of installed apps, screenshots and data from WeChat, Outlook, Twitter, Facebook, Gmail and Chrome. Google removed the offending apps at the time.
According to XDA-Developers, MediaTek says the vulnerability affects MediaTek devices with Linux Kernel versions 3.18, 4.4, 4.9, or 4.14 running Android versions 7 Nougat, 8 Oreo, or 9 Pie.
MediaTek devices running Android 10 are not vulnerable since "the access permission of CMDQ device nodes is also enforced by SELinux", the company said.
MediaTek actually had patches available for the flaw in May 2019, which were rolled out by Amazon for its Fire OS devices. However, many OEMs using affected MediaTek chips hadn't applied the fix and so the company reportedly sought Google's help.
Now that Google has released a fix in its Android update, users with a MediaTek device should install them from their OEM.