Your android lock screen can be cracked in under a minute—here’s how
Plug in a cable, wait 45 seconds, and the PIN falls. That is all it takes for the flaw tagged CVE-2026-20435 to peel open a MediaTek-powered android handset, decrypt its storage and dump every selfie, banking token and drunken text message straight into a laptop running open-source forensics tools.
Researchers at Coastal Code replicated the attack last night on a £120 supermarket phone and a Samsung A14. Both share the same silicon heart—MediaTek’s boot ROM—and both handed over the user-defined PIN before the android logo even appeared. The trick abuses a race condition in the chip’s secure boot chain: attackers slip a command between the moment the processor wakes and the moment it locks down the key material, grabbing the 256-bit disk-encryption key while the OS is still yawning.

The patch gap turns cheap phones into permanent evidence bags
Google’s February bulletin lists a fix, but the queue for updates is a bureaucratic slalom. MediaTek ships the patch to vendors; vendors test it against their skins; carriers demand network certification. Result: eleven-month-old handsets are already orphaned, and second-hand models circulating on eBay remain grenades with the pin half-pulled. The cheapest devices—those marketed at teenagers, delivery riders and cash-strapped parents—are precisely the ones whose bootloaders will never taste an OTA update.
Physical access is still the barrier, yet that is a low fence. Office cleaners, airport security, jealous ex-partners, over-eager border guards: anyone with a pocket-sized Linux live USB and a £3 cable becomes a one-person intelligence agency. The toolkit is on GitHub, well-documented and enthusiast-friendly; no nation-state budget required.
Google’s spokesperson says the company is “working with partners to accelerate deployment.” Translation: the cavalry will arrive, but only for flagships that still receive marketing love. For the 1.8 billion Androids that cost under $200, the fix is already a myth.
Short of buying a Pixel, users have two moves: lengthen the PIN to the maximum 16 digits—patterns are trivial to shoulder-surf—and power the phone down before it leaves your sight. A cold device keeps its keys scrambled; a sleeping one whispers them to the first cable that says hello. Paranoid? Maybe. But the clock on the lab bench keeps resetting to 00:45, and every second counts.
