OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others
A security researcher has detailed a strategy to gain root access on major Android devices by exploiting vulnerabilities in OEM-specific kernel drivers. The research covers flagship devices from Samsung, Xiaomi, Oppo, OnePlus, and Realme.
Why it matters
This highlights significant security risks in the Android ecosystem caused by manufacturer-specific customizations and kernel-level vulnerabilities.
Part 1 of a series that takes an unprivileged Android app to root on Samsung, Xiaomi, and Oppo/OnePlus/Realme devices, with a single strategy.
On Android, every third-party app runs in a sandboxed context called untrusted_app . If you ask five offensive security researchers how to go from this context to root , you will most likely get five different strategies, and each has its own trade-offs. Here, I describe the one I took and why, measured against three properties I use as a yardstick throughout:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in