/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft researchers find high severity vulnerabilities in mce Systems' framework used by Android apps from carriers including AT&T, Telus, Rogers, and Bell

Microsoft security researchers have found high severity vulnerabilities in a framework used by Android apps from multiple large international mobile service providers.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is the latest entry in a decade-long pattern: the software that carriers and device makers preinstall on Android phones is repeatedly the weakest link. Check Point's Certifi-Gate research in 2015 showed remote-support tooling could yield full device control, Kryptowire's 2018 findings on Asus, LG, Essential, and ZTE firmware additions documented the same class of flaw, and a DHS official said at BlackHat that year that [[a:932259|DHS-funded researchers had found major vulnerabilities in phones from all four major US carriers]].

What is new here is the layer being implicated: not firmware or a single carrier app, but a shared framework from mce Systems embedded in Android apps across AT&T, Telus, Rogers, and Bell — meaning one vendor's code ships inside many carriers' software simultaneously, and Microsoft's researchers, not the carriers, found it.

First-order effects

  • AT&T, Telus, Rogers, and Bell must now audit and patch every Android app that bundles the mce Systems framework, and coordinate fixes with mce Systems rather than shipping updates on their own schedules.
  • Customers of those carriers with the affected apps installed are exposed to high-severity flaws until carrier app updates reach their devices.

Second-order effects

  • Other carriers that license mce Systems' framework face the same exposure and the same patching burden, since the vulnerability travels with the shared code rather than with any one carrier.
  • Carriers get fresh evidence that preinstalled software is a liability they do not fully control, pressuring them to scrutinize third-party vendors like mce Systems the way Kryptowire's findings pressured device makers.

Third-order effects

  • If the pattern holds — from Certifi-Gate through Kryptowire to this disclosure — the recurring lesson is that the Android supply chain's weakest layer is preinstalled carrier and OEM code that sits outside Google's patch pipeline, echoing the 2015 study finding 87% of devices unpatched. Expect growing calls for vendor code audits and disclosure obligations covering preinstalled software, not just the OS.

The trend: Android security risk is migrating down the supply chain from the OS to preinstalled carrier and OEM software, with outside researchers — Check Point, Kryptowire, now Microsoft — repeatedly finding what the shippers missed.