DigiNews

Tech Watch by Johan Denoyer

← Back to articles

OEMpocalypse Now: A Generic Exploitation Strategy from Android untrusted app to root

Quality: 8/10 Relevance: 9/10

Summary

This security research post introduces OEMpocalypse, a three-chain method to escape Android sandboxes and root devices by exploiting a page UAF in OEM kernel drivers. It covers Stage 1 sandbox escapes, Stage 2 page-level faults, and discusses coverage across Samsung, Xiaomi, and Oppo/OnePlus/Realme devices, along with defensive takeaways and the need to audit OEM IPCs and kernel drivers. The article sets the stage for subsequent OEM-specific analyses.

🚀 Service construit par Johan Denoyer