One generic exploit chain to root them all: Samsung, Xiaomi and Oppo Android flagships

jedisct1 · x · 2026-09-01

Security researcher Lukas Maar published part one of a series, "OEMpocalypse Now," demonstrating a single generic strategy to escalate from an Android third-party app's untrustedapp sandbox all the way to root.

The core idea: target only OEM-written code — exploit a page use-after-free in an OEM-specific kernel driver, reached via an OEM-specific sandbox escape where SELinux policy requires one.

The strategy is measured against reliability (100% success), portability (minimal per-kernel/OEM/device adjustment), and universality (max device coverage). Instantiated once per major OEM, the resulting chains cover all Samsung flagships (Galaxy S23 through S26 and recent Z series), a large share of Xiaomi mid-range to flagship devices, and recent Oppo, OnePlus, and Realme flagships.

Original post →

More from Safety

Safety channel →