/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Check Point details MediaTek DSP firmware vulnerabilities in some Android smartphones that could be exploited to eavesdrop; MediaTek released patches in October

PCMag Nathaniel Mott

Context & Ripple Effects

This is the second time in two years a major mobile chipset maker has had to patch its signal-processing silicon: Qualcomm fixed six flaws in its Snapdragon DSP in August 2020 that allowed silent phone takeover (Qualcomm's Snapdragon DSP patches), and Google shipped a fix for a MediaTek rootkit exploit affecting millions of devices only after it circulated publicly for nearly a year (the MediaTek chipset rootkit).

Check Point — which flagged Android remote-control risk back in 2015 with Certifi-Gate — is now detailing MediaTek DSP firmware bugs that enable eavesdropping, with fixes already released in October. The throughline: the DSP, the always-on audio brain of a phone, keeps turning up as an attack surface independent of the main OS.

First-order effects

  • Owners of affected Android smartphones face eavesdropping risk until their device maker pushes MediaTek's October patches downstream — the chip vendor's fix alone doesn't secure a phone.
  • Check Point gains another high-profile disclosure win, reinforcing its position as the researcher most consistently surfacing Android platform-level flaws.

Second-order effects

  • Phone OEMs shipping MediaTek silicon are forced into expedited firmware validation and rollout cycles, since a delayed update leaves their customers exposed even after the chipmaker acts.
  • Qualcomm and other DSP designers face pressure to audit their own signal-processing firmware harder, as each disclosed bug raises the odds researchers treat the DSP as a standard hunting ground.

Third-order effects

  • If the pattern holds — DSP bugs at both leading mobile chip vendors, plus later codec-level RCE findings like the ALAC flaw shared by Qualcomm and MediaTek devices — the industry moves toward treating offload processors and shared media code as first-class security surfaces requiring their own patch SLAs, not just the application processor.

The trend: Mobile chipset firmware — DSPs and audio subsystems in particular — is becoming a recurring, cross-vendor attack surface that security researchers now probe systematically.

Discussion

  • @checkpointsw Check Point on x
    @_CPResearch_ discovered vulnerabilities in the global smartphone chip leader since Q3 2020, #MediaTek's chips, placed 37% of all #smartphones. If exploited, attackers could potentially spy on users from an #Android app. Details, here: https://blog.checkpoint.com/ ... #cybersecur…
  • @pcmag @pcmag on x
    Roughly 37% of all smartphones and Internet of Things devices have a security vulnerability that could be used to eavesdrop on users. https://www.pcmag.com/...