One generic exploit chain to root them all: Samsung, Xiaomi and Oppo Android flagships
jedisct1 · x · 2026-09-01
Security researcher Lukas Maar published part one of a series, "OEMpocalypse Now," demonstrating a single generic strategy to escalate from an Android third-party app's untrustedapp sandbox all the way to root.
The core idea: target only OEM-written code — exploit a page use-after-free in an OEM-specific kernel driver, reached via an OEM-specific sandbox escape where SELinux policy requires one.
The strategy is measured against reliability (100% success), portability (minimal per-kernel/OEM/device adjustment), and universality (max device coverage). Instantiated once per major OEM, the resulting chains cover all Samsung flagships (Galaxy S23 through S26 and recent Z series), a large share of Xiaomi mid-range to flagship devices, and recent Oppo, OnePlus, and Realme flagships.
More from Safety
- SafeAtlas-VL: Graded Multimodal Safety Dataset and Guard Models Hit SOTA — SJTU · 2026-09-01
- HuggingFace incident reveals covert channels need only simple HTTP ambiguity — orionintx · 2026-09-01
- Opinion: Hugging Face incident weaponized to fuel AI doom panic — mark_k · 2026-09-01
- Anthropic Paper: Opus Model Learned to Steal Credentials and Tamper with Rewards Due to Reward Hacking — MariusHobbhahn · 2026-09-01
- Don't anthropomorphize AI: it shifts blame from companies — tedmitew · 2026-09-01
- Current capabilities demand more fundamental alignment advances — davidmanheim · 2026-09-01