• Sources: research post, HN discussion
  • Summary: The strategy targets only OEM-written code, because an OEM component ships across that vendor's lineup regardless of the chipset underneath. Each chain pairs a page use-after-free in an OEM kernel driver with an OEM sandbox escape where SELinux policy gates the driver. A page-level primitive sidesteps slab hardening such as CONFIG_SLAB_BUCKETS and CONFIG_RANDOM_KMALLOC_CACHES, usually needs no KASLR leak, and is data-only so CFI does not constrain it.
  • Why it matters: The demonstrations run as apps with no declared permissions on stock, bootloader-locked devices, so the exposure does not depend on sideloading or an unlocked bootloader.
  • Follow-up: The post is dated 2026-08-31, is part one of a series, and names no CVEs and no patch status, so assigned identifiers and vendor fixes are the open items.

send feedback on this story