Indian Government's Security Alert: Millions of Smartphones & TVs Vulnerable Due to MediaTek Chipset Flaws.
  • 715 views
  • 2 min read

The Indian government, through its cybersecurity watchdog, the Indian Computer Emergency Response Team (CERT-In), has issued a high-risk security advisory concerning vulnerabilities discovered in MediaTek chipsets. This warning impacts millions of smartphone and TV users in India and globally, as MediaTek chips are widely used in Android devices. These vulnerabilities could allow attackers to gain unauthorized access, steal sensitive information, execute arbitrary code, and cause denial-of-service (DoS) attacks on affected systems.

CERT-In's advisory highlights that the vulnerabilities exist due to flaws in various components, including the Android Framework, System, Kernel, and hardware-specific components from MediaTek. Successful exploitation of these vulnerabilities could lead to severe consequences, including privilege escalation, data theft, and the ability for attackers to control devices remotely.

Several reports indicate that the vulnerabilities affect a wide range of Android versions, including 12, 12L, 13, 14, and 15. This means a significant portion of Android devices currently in use are potentially at risk. Popular smartphone brands such as Samsung, Realme, OnePlus, Xiaomi, Vivo, Nothing, and Infinix, which utilize MediaTek chipsets in many of their models, are particularly affected.

One of the most concerning vulnerabilities, CVE-2024-20154, is a stack overflow issue in affected chipsets' modems that could lead to remote code execution if a device connects to an attacker-controlled base station. This vulnerability has been given a "critical" severity assessment, as it doesn't require any user interaction or additional privileges for exploitation. Another significant vulnerability, CVE-2025-20678, impacts over 80 different chipset models and involves uncontrolled recursion in the IMS (IP Multimedia Subsystem) service, potentially enabling remote denial-of-service attacks. CVE-2025-20671 represents a heap overflow vulnerability in MediaTek's Bluetooth driver, allowing local escalation of privilege.

MediaTek has acknowledged the vulnerabilities and has reportedly notified device manufacturers about the issues and provided patches. The company states that device manufacturers were informed about the vulnerabilities at least two months prior to public disclosure, giving them time to develop and deploy security updates.

To mitigate the risks posed by these vulnerabilities, CERT-In advises users and OEMs to take the following steps:

  • Install Security Updates Promptly: Users should install the latest security patches as soon as they are released by their device manufacturers. These patches address the identified vulnerabilities and help prevent exploitation.
  • Download Apps from Trusted Sources: Users should only download apps from trusted sources like the Google Play Store. Avoiding third-party or unknown sources reduces the risk of installing malicious apps that could exploit vulnerabilities.
  • Enable Google Play Protect: Enabling Google Play Protect helps detect and block potentially harmful apps before they can be installed on a device.
  • Review App Permissions: Users should carefully review the permissions requested by apps and restrict unnecessary access to their data.
  • Be Cautious of Unsolicited Messages and Links: Users should be wary of unsolicited messages, emails, or links, especially those asking for personal information or credentials. Phishing attacks are a common method used by hackers to exploit vulnerabilities.
  • Keep Devices Updated: Regularly updating the operating system and applications is crucial for maintaining security.
  • Enable Automatic Updates: Enabling automatic updates ensures that devices receive the latest security patches and updates as soon as they are available.

The Indian government's warning highlights the importance of proactive cybersecurity measures and the need for users to stay informed about potential threats. By taking the recommended steps, users can significantly reduce their risk of being affected by these vulnerabilities and protect their personal data and devices from cyberattacks. It is also crucial for device manufacturers to prioritize the timely release of security patches to address these vulnerabilities and ensure the safety of their users.


Writer - Isha Sharma
Passionate about culture, society, and sports, Isha brings a fresh, insightful perspective to her early journalism. She's keen on exploring her city's evolving cultural landscape, covering local arts, music, and community events. Isha is developing an engaging, informative writing style to capture artistic vibrancy and diversity. She's also interested in how cultural trends reflect and influence broader social dynamics, alongside her enthusiasm for the world of sports.
Advertisement

Latest Post


Entertainment  |  Aug 06, 2025
The highly anticipated trailer for Season 2 of *My Life With The Walter Boys* has been released, giving fans a glimpse into the drama, romance, and self-discovery that awaits. The series is set to stream on Netflix on August 28, 2025. Season 2 picks...

World  |  Aug 06, 2025
A recent report by the Public Accounts Committee (PAC) has brought to light a concerning imbalance in the Delhi Police's manpower structure, revealing a disproportionately high number of commanders compared to constables. This observation raises ques...

Technology  |  Aug 06, 2025
The Indian Computer Emergency Response Team (CERT-In), under the Ministry of Electronics and Information Technology, has issued a high-severity alert for Apple users in India, warning of multiple security vulnerabilities affecting a wide range of App...

Business  |  Aug 06, 2025
Sri Lotus Developers IPO made a strong debut on the stock exchanges, listing at a premium of approximately 19% above its issue price of ₹150. On the Bombay Stock Exchange (BSE), the shares opened at ₹179. 10, a 19. 4% increase, while on the National St...

Advertisement
Entertainment  |  Aug 06, 2025
"Mahavatar Narsimha," an animated devotional action drama directed by Ashwin Kumar, has achieved a historic milestone by becoming the first Indian animated film to cross the ₹100 crore mark at the domestic box office. Released on July 25, 2025, the f...

World  |  Aug 06, 2025
The Indian government is firmly against lowering the age of consent from 18, cautioning that doing so would increase the risks of trafficking and other forms of child abuse. The Centre has conveyed its position to the Supreme Court, which is currentl...

Entertainment  |  Aug 06, 2025
Yuzvendra Chahal has recently addressed his divorce from Dhanashree Verma and the stir caused by his "Be Your Own Sugar Daddy" T-shirt during the final hearing. In a podcast interview with Raj Shamani, the cricketer opened up about the reasons behind...

World  |  Aug 06, 2025
In its August 2025 monetary policy review, the Reserve Bank of India's (RBI) Monetary Policy Committee (MPC), led by Governor Sanjay Malhotra, has decided to maintain the repo rate unchanged at 5. 5%. This decision was announced on Wednesday, followin...

Advertisement
About   •   Terms   •   Privacy
© 2025 DailyDigest360