Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Many Mobile Devices Contain A Chip With A Security Risk

Many Mobile Devices Contain A Chip With A Security Risk

Randy Hall By Randy Hall Updated Nov 2025 3 min read Share

A new, high severity vulnerability has been found in Qualcomm's MSM (Mobile Station Modem) chips, including the company's latest 5G-capable versions. The security issue could allow hackers to access a user's call history, text messages, and even listen in on their conversations.

Unfortunately, given the ubiquity of these chips in today's smartphones, this flaw impacts some 40 percent of the phones in use today. That is including phones offered by some of the biggest vendors on the market today, including, but not limited to LG, OnePlus, Google, and Samsung.

Researchers at Check Point discovered the vulnerability, which is being tracked as CVE-2020-11292.

Yaniv Balmas, the head of Cyber Research at Check Point, had this to say about the issue:

"We ultimately proved a dangerous vulnerability did in fact exist in these chips, revealing how an attacker could use the Android OS itself to inject malicious code into mobile phones, undetected.

Going forward, our research can hopefully open the door for other security researchers to assist Qualcomm and other vendors to create better and more secure chips, helping us foster better online protection and security for everyone."

For their part, Qualcomm has acted quickly and responsibly. They have been providing security updates designed to address the flaw, and making them available to all vendors using the chips in December 2020.

What that means to the average end user is that if you have a newer device that's still receiving regular system and security updates, you should be protected. However that still leaves legions of cellphone users potentially vulnerable. For instance, according to industry data, some 19 percent of Android devices in use today are still running Android Pie (9.0), which was released in August 2018, and about 9 percent are using Android 8.1 (Oreo), which was released in 2018.

If you're one of the users still relying on these older versions, you'll want to make sure to manually grab the latest update to be sure you're protected.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime