- Sources: research post, HN discussion
- Summary: The strategy targets only OEM-written code, because an OEM component ships across that vendor's lineup regardless of the chipset underneath. Each chain pairs a page use-after-free in an OEM kernel driver with an OEM sandbox escape where SELinux policy gates the driver. A page-level primitive sidesteps slab hardening such as
CONFIG_SLAB_BUCKETS and CONFIG_RANDOM_KMALLOC_CACHES, usually needs no KASLR leak, and is data-only so CFI does not constrain it. - Why it matters: The demonstrations run as apps with no declared permissions on stock, bootloader-locked devices, so the exposure does not depend on sideloading or an unlocked bootloader.
- Follow-up: The post is dated 2026-08-31, is part one of a series, and names no CVEs and no patch status, so assigned identifiers and vendor fixes are the open items.
send feedback on this story