An urgent security alert has been issued for Android users, warning of a critical vulnerability that could enable cyber criminals to bypass the lock screen on certain devices. The flaw, identified by the Donjon security team, poses a significant risk as attackers can exploit it to access personal data and all content stored on the phone within a minute.
Researchers demonstrated the exploit by connecting a vulnerable phone to a laptop via USB, revealing how they could retrieve the device’s PIN, decrypt its storage, and access sensitive files, including data from software wallets, in under 60 seconds.
The vulnerability, known as CVE-2026-20435, specifically impacts Android devices powered by MediaTek processors, which are commonly found in budget-friendly smartphones, potentially putting a large number of devices at risk.
Security experts explained that the flaw allows attackers to extract encryption keys before the system fully boots up, effectively bypassing security measures like full-disk encryption and lock screen protection.
To mitigate the risk posed by this vulnerability, users are advised to check their device’s processor information in the Settings menu and ensure that their phone runs on a MediaTek chip. If so, it is crucial to promptly install any available security updates. MediaTek has already released a fix, but users must wait for individual device manufacturers to distribute it through software updates. Keeping devices up to date with the latest patches is essential for protection.
It is important to note that this attack requires physical access to the device. By keeping your phone secure and regularly updated, the risk of exploitation is significantly reduced. However, users with older devices that no longer receive updates should exercise caution or consider upgrading to a more secure device.