A rootkit exploit affecting MediaTek chipsets in millions of Android devices gets a patch from Google, almost a year after the exploit was first revealed online
Mishaal Rahman / XDA Developers :
Context & Ripple Effects
This patch closes a chapter that opened when the MediaTek rootkit exploit was published online with no vendor fix available, leaving millions of budget and mid-range Android devices exposed for the better part of a year. It fits a long line of chipset-level Android flaws: Qualcomm's "Quadrooter" driver flaws gave malicious apps root access in 2016, Qualcomm patched another critical chipset flaw across 46 chipsets in 2019, and Check Point later found MediaTek DSP firmware bugs that could enable eavesdropping.
The through-line is patch latency: after Stagefright, Google spent a year issuing fixes for 115 related flaws, and the same year-long gap between public disclosure and shipped patch repeats here. Because the vulnerable code sits in silicon firmware rather than an app, only Google and MediaTek can deliver the fix — device owners can't patch around it.
First-order effects
- Owners of MediaTek-powered Android devices finally receive a working fix for a publicly known rootkit exploit, roughly a year after attackers could have studied it online.
- OEMs shipping MediaTek chipsets must now push Google's patch through their own update pipelines, where low-cost devices historically lag longest.
Second-order effects
- MediaTek faces the scrutiny Qualcomm absorbed after Quadrooter — buyers of its chipsets gain reason to demand faster firmware response times as a procurement condition.
- Security researchers get fresh evidence that publishing unpatched chipset exploits forces action, shaping future disclosure decisions against MediaTek-class vendors.
Third-order effects
- If chipset firmware keeps producing multi-year exposure windows, Android's security model shifts further toward holding silicon vendors — not just Google or OEMs — accountable for patch timelines, pressuring longer supported lifetimes for budget devices.
The trend: Android security is repeatedly bottlenecked at the chipset layer, where disclosure-to-patch gaps stretch toward a year and leave the cheapest devices exposed longest.