
Ledger researchers say a flaw in some MediaTek-powered Android phones could let attackers extract encrypted data, including private keys and passwords, within seconds through a USB connection if they gain device access.
Ledger security researchers reported a major flaw affecting some Android smartphone chips that could allow attackers to extract encrypted user data, including passwords and private keys, in seconds using a USB connection. The new report broadens earlier coverage that focused on hot wallet seed phrases and the MediaTek Dimensity 7300 chip, indicating the vulnerability can expose a wider range of sensitive data on affected devices. Existing reporting said the attack requires physical access, and Ledger Donjon had previously linked the issue to a weakness in the MediaTek secure boot chain on some Android phones.