Your android lock screen can be cracked in under a minute—here’s how

Plug in a cable, wait 45 seconds, and the PIN falls. That is all it takes for the flaw tagged CVE-2026-20435 to peel open a MediaTek-powered android handset, decrypt its storage and dump every selfie, banking token and drunken text message straight into a laptop running open-source forensics tools.

Researchers at Coastal Code replicated the attack last night on a £120 supermarket phone and a Samsung A14. Both share the same silicon heart—MediaTek’s boot ROM—and both handed over the user-defined PIN before the android logo even appeared. The trick abuses a race condition in the chip’s secure boot chain: attackers slip a command between the moment the processor wakes and the moment it locks down the key material, grabbing the 256-bit disk-encryption key while the OS is still yawning.

The patch gap turns cheap phones into permanent evidence bags

The patch gap turns cheap phones into permanent evidence bags

Google’s February bulletin lists a fix, but the queue for updates is a bureaucratic slalom. MediaTek ships the patch to vendors; vendors test it against their skins; carriers demand network certification. Result: eleven-month-old handsets are already orphaned, and second-hand models circulating on eBay remain grenades with the pin half-pulled. The cheapest devices—those marketed at teenagers, delivery riders and cash-strapped parents—are precisely the ones whose bootloaders will never taste an OTA update.

Physical access is still the barrier, yet that is a low fence. Office cleaners, airport security, jealous ex-partners, over-eager border guards: anyone with a pocket-sized Linux live USB and a £3 cable becomes a one-person intelligence agency. The toolkit is on GitHub, well-documented and enthusiast-friendly; no nation-state budget required.

Google’s spokesperson says the company is “working with partners to accelerate deployment.” Translation: the cavalry will arrive, but only for flagships that still receive marketing love. For the 1.8 billion Androids that cost under $200, the fix is already a myth.

Short of buying a Pixel, users have two moves: lengthen the PIN to the maximum 16 digits—patterns are trivial to shoulder-surf—and power the phone down before it leaves your sight. A cold device keeps its keys scrambled; a sleeping one whispers them to the first cable that says hello. Paranoid? Maybe. But the clock on the lab bench keeps resetting to 00:45, and every second counts.