368 lines
19 KiB
Markdown
368 lines
19 KiB
Markdown
|
|
# Pixel Root Exploits — Research Notes
|
||
|
|
## Last Updated: 2026-03-03
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## TIER 1 — PUBLIC PoC, HIGH RELIABILITY
|
||
|
|
|
||
|
|
### CVE-2024-0044 (run-as any app)
|
||
|
|
- **Type:** Userspace privilege escalation
|
||
|
|
- **Affected:** Android 12, 13 (patched in 14 QPR2 / March 2024 ASB)
|
||
|
|
- **Root required:** No — from ADB shell (UID 2000)
|
||
|
|
- **What it does:** Abuse createSessionInternal in PackageInstallerService.java to
|
||
|
|
run as any installed app's UID — full access to that app's data sandbox
|
||
|
|
- **PoC:** https://github.com/0xbinder/CVE-2024-0044 (multiple public repos)
|
||
|
|
- **Implementation:** Push malicious APK, extract target UID, invoke `run-as <pkg>`
|
||
|
|
after exploiting the installer session — bypasses run-as authorization check
|
||
|
|
- **AUTARCH status:** Already in scope, partially implemented
|
||
|
|
|
||
|
|
### CVE-2024-31317 (Zygote injection, WRITE_SECURE_SETTINGS escalation)
|
||
|
|
- **Type:** Code exec as any app via Zygote
|
||
|
|
- **Affected:** Android 12, 13, 14 (patched in 14 QPR2)
|
||
|
|
- **Prerequisite:** WRITE_SECURE_SETTINGS permission (shell/UID 2000 has this)
|
||
|
|
- **What it does:** Sets hidden_api_blacklist_exemptions global setting to include
|
||
|
|
newline-injected Zygote commands. System Server passes value unsanitized to
|
||
|
|
Zygote socket -> executes as any app's UID via new Zygote fork
|
||
|
|
- **PoC:** https://blog.flanker017.me/cve-2024-31317/ (writeup + PoC)
|
||
|
|
- **Chain:** ADB shell -> WRITE_SECURE_SETTINGS -> arbitrary app UID -> data access
|
||
|
|
- **AUTARCH status:** In scope
|
||
|
|
|
||
|
|
### Pixel_GPU_Exploit (Mali GPU, Android 14)
|
||
|
|
- **CVEs:** CVE-2023-6241 (integer overflow in gpu_pixel_handle_buffer_liveness_update_ioctl)
|
||
|
|
+ information leak in timeline stream message buffers
|
||
|
|
- **Researcher:** 0x36 (simo36)
|
||
|
|
- **Repo:** https://github.com/0x36/Pixel_GPU_Exploit
|
||
|
|
- **Affected:** Pixel 7, 7 Pro, 8 Pro — Android 14, October/November 2023 ASBs
|
||
|
|
- **Access level:** untrusted_app context (no ADB required)
|
||
|
|
- **What it does:** Arbitrary kernel R/W -> disables SELinux -> elevates to root
|
||
|
|
- **Success rate:** ~100% on tested devices per researcher
|
||
|
|
- **Requires:** Hardcoded kernel offsets (kthreadd_task, selinux_state,
|
||
|
|
task_struct, anon_pipe_buf_ops) — must be calculated per build
|
||
|
|
- **Stealth:** LOW (kernel exploit, likely leaves traces)
|
||
|
|
|
||
|
|
### CVE-2025-0072 (Mali GPU MTE bypass, Pixel 7/8/9)
|
||
|
|
- **Type:** Kernel UAF via Mali CSF queue binding, bypasses MTE on Pixel 8
|
||
|
|
- **Affected:** Pixel 7, 8, 9 series (Mali CSF architecture)
|
||
|
|
- **Patched:** May 2025 ASB (Mali driver r54p0)
|
||
|
|
- **What it does:** Manipulates CSF queue binding/unbinding -> UAF via user-space
|
||
|
|
page mappings that bypass kernel MTE tag checking -> arbitrary kernel code exec
|
||
|
|
- **Research:** GitHub Blog writeup — demonstrated root + SELinux disable on Pixel 8
|
||
|
|
- **PoC:** Research-grade, no full public PoC as of 2026-03 (GitHub Blog article)
|
||
|
|
- **Stealth:** LOW
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## TIER 2 — KNOWN EXPLOITABLE, LIMITED/NO PUBLIC PoC
|
||
|
|
|
||
|
|
### CVE-2023-21400 (io_uring double-free, kernel 5.10)
|
||
|
|
- **Type:** Double-free in io_uring.c due to improper locking
|
||
|
|
- **Affected:** GKI kernel 5.10 — confirmed on Pixel 7
|
||
|
|
- **Technique:** Dirty Pagetable exploitation method
|
||
|
|
- **PoC status:** Research PoC by Nicolas Wu, not widely public
|
||
|
|
- **Related:** bad_io_uring repo (CVE-2022-20409) at https://github.com/Markakd/bad_io_uring
|
||
|
|
(different CVE but same attack surface)
|
||
|
|
- **Note:** Google disabled io_uring in ChromeOS, restricted on Android via seccomp-bpf
|
||
|
|
— check if seccomp filter blocks target io_uring calls first
|
||
|
|
|
||
|
|
### CVE-2023-20938 (Binder UAF)
|
||
|
|
- **Type:** Use-after-free in binder_transaction_buffer_release
|
||
|
|
- **Affected:** GKI kernels 5.4 and 5.10, all OEMs
|
||
|
|
- **Access:** From untrusted app
|
||
|
|
- **Patched:** Android Security Bulletin Feb 2023 + Jul 2023
|
||
|
|
- **What it does:** One-way binder transactions with crafted data causes improper
|
||
|
|
deallocation -> UAF -> arbitrary kernel access -> root
|
||
|
|
- **PoC status:** Android Red Team demonstrated it internally, no clean public PoC
|
||
|
|
- **Reference:** https://androidoffsec.withgoogle.com/posts/attacking-android-binder-analysis-and-exploitation-of-cve-2023-20938/
|
||
|
|
|
||
|
|
### CVE-2024-53104 (UVC driver OOB write, actively exploited by Cellebrite)
|
||
|
|
- **Type:** Out-of-bounds write in uvc_parse_format(), heap buffer overflow
|
||
|
|
- **Affected:** Linux kernel / Android — actively exploited in wild (CISA KEV Feb 2025)
|
||
|
|
- **Prerequisite:** PHYSICAL USB access (requires plugging in malicious USB video device)
|
||
|
|
- **Patched:** February 2025 ASB
|
||
|
|
- **Exploitation context:** Cellebrite used this as part of spyware install chain
|
||
|
|
- **PoC status:** PoC released after patch (Cyware, Feb 2025)
|
||
|
|
- **Attack vector:** Craft malicious USB UVC device that sends UVC_VS_UNDEFINED frames
|
||
|
|
|
||
|
|
### CVE-2024-32896 (Pixel Firmware, actively exploited)
|
||
|
|
- **Type:** Logic error in privilege escalation handling in Pixel firmware
|
||
|
|
- **Affected:** Pixel devices specifically (not generic Android)
|
||
|
|
- **Patched:** Android 14 QPR3 (full fix), earlier partial fix in CVE-2024-29748
|
||
|
|
- **CVSS:** 7.8 HIGH (CISA adjusted to 8.1)
|
||
|
|
- **PoC status:** No public PoC — was used in targeted attacks
|
||
|
|
- **Note:** CVE-2024-29748 was the companion bug — allowed interrupting factory reset
|
||
|
|
triggered by device admin app (useful for anti-forensics on seized devices)
|
||
|
|
|
||
|
|
### CVE-2024-43093 (Framework ExternalStorageProvider path bypass)
|
||
|
|
- **Type:** Unicode normalization bypass in shouldHideDocument()
|
||
|
|
- **Affected:** Android 12, 13, 14, 15 — patched Nov 2024 ASB
|
||
|
|
- **Access:** No special privileges needed, exploitable from untrusted app
|
||
|
|
- **What it does:** Access Android/data, Android/obb, Android/sandbox directories
|
||
|
|
and subdirectories — bypasses path filter via Unicode confusion
|
||
|
|
- **Exploitation:** Actively used in targeted espionage campaigns (commercial spyware)
|
||
|
|
- **PoC:** No public PoC
|
||
|
|
|
||
|
|
### CVE-2023-32233 (Netfilter nf_tables UAF)
|
||
|
|
- **Type:** UAF in nf_tables batch requests
|
||
|
|
- **What it does:** Corrupts netfilter internal state -> kernel memory corruption
|
||
|
|
- **Note:** Requires CAP_NET_ADMIN or unprivileged user namespace on some configs
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## TIER 3 — SEMI-ROOT / ELEVATED ACCESS (NO FULL KERNEL EXPLOIT)
|
||
|
|
|
||
|
|
### fastboot boot (temporary root, requires unlocked bootloader)
|
||
|
|
- **Method:** Extract stock boot.img/init_boot.img -> patch with Magisk -> `fastboot boot <img>`
|
||
|
|
- **Pixel specifics:**
|
||
|
|
- Pixel 6 (Oriole/Raven): patches boot.img
|
||
|
|
- Pixel 7+ (Cheetah/Panther): patches init_boot.img (Android 13+)
|
||
|
|
- Pixel 8/9: patches init_boot.img
|
||
|
|
- **Key command sequence:**
|
||
|
|
```
|
||
|
|
fastboot reboot bootloader
|
||
|
|
fastboot boot magisk_patched_init_boot.img
|
||
|
|
```
|
||
|
|
- **Temporary:** Yes — does NOT survive reboot unless you flash permanently
|
||
|
|
- **Prerequisite:** OEM unlock + bootloader unlock (wipes device on first unlock)
|
||
|
|
- **Tool:** PixelFlasher GUI (https://github.com/badabing2005/PixelFlasher)
|
||
|
|
- **Reliability:** HIGH
|
||
|
|
- **Stealth:** LOW (bootloader unlock trips verified boot / dm-verity)
|
||
|
|
|
||
|
|
### Shizuku / arish (UID 2000 elevated shell)
|
||
|
|
- **What it is:** app_process Java process running as shell (UID 2000) exposing
|
||
|
|
privileged Android APIs over Binder
|
||
|
|
- **Capabilities at UID 2000:**
|
||
|
|
- WRITE_SECURE_SETTINGS
|
||
|
|
- INSTALL_PACKAGES
|
||
|
|
- READ_LOGS
|
||
|
|
- Access /data/local/tmp
|
||
|
|
- pm, am, settings commands
|
||
|
|
- Bind to many system services directly
|
||
|
|
- **Limitation:** Cannot access other apps' data sandboxes directly (still needs
|
||
|
|
run-as or a kernel exploit for that)
|
||
|
|
- **AUTARCH relevance:** Archon app runs at UID 2000 via app_process — this IS
|
||
|
|
Shizuku-equivalent. Chain with CVE-2024-31317 for full arbitrary app access.
|
||
|
|
- **Reliability:** HIGH (well-understood, stable)
|
||
|
|
- **Stealth:** MODERATE (process visible in ps output)
|
||
|
|
|
||
|
|
### DSU (Dynamic System Updates) for research access
|
||
|
|
- **What it does:** Boots a GSI (Generic System Image) alongside the main OS in
|
||
|
|
a separate dynamic partition — does NOT modify main OS
|
||
|
|
- **Security posture:** The GSI runs with its own SELinux, but shares hardware
|
||
|
|
- **Exploitation angle:** GSI can be a custom Android build with root/userdebug —
|
||
|
|
use DSU to boot rooted environment without unlocking main OS bootloader
|
||
|
|
- **Prerequisite:** Requires MANAGE_DYNAMIC_SYSTEM permission (signature-level) or
|
||
|
|
ADB to trigger (shell can call `am start-activity` against DynamicSystem service)
|
||
|
|
- **Limitation:** Main OS data partitions not mounted in DSU guest
|
||
|
|
- **Reliability:** MEDIUM (device-dependent support)
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## BOOTLOADER NOTES (Pixel-specific)
|
||
|
|
|
||
|
|
- All Pixel phones support OEM unlock + bootloader unlock via fastboot
|
||
|
|
- Bootloader unlock WIPES the device (data partition formatted)
|
||
|
|
- After unlock: `fastboot boot <img>` works for temporary boots without flashing
|
||
|
|
- Verified Boot is tripped — apps like banking/DRM will detect unlocked bootloader
|
||
|
|
- KernelSU + Wild GKI kernel: modern alternative to Magisk for Pixel 6-9
|
||
|
|
- Uses LKM (Loadable Kernel Module) mode — patches only init_boot.img
|
||
|
|
- More stealth-compatible than Magisk for Play Integrity bypass
|
||
|
|
- APatch: newer option, patches kernel via kpatch binary method
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## ANDROID 15/16 SPECIFIC — NEW ENTRIES (researched 2026-03-03)
|
||
|
|
|
||
|
|
### CVE-2025-0072 — UPDATE: Public PoC confirmed
|
||
|
|
|
||
|
|
**Confirmed details (from GitHub Security Lab article):**
|
||
|
|
- Affects Pixel 7, 8, AND 9 series (all Immortalis/Valhall CSF architecture)
|
||
|
|
- Pixel 9 running Android 15 IS affected if patch level pre-2025-05-05
|
||
|
|
- Exploitation chain: untrusted app -> Mali GPU ioctl -> CSF queue UAF ->
|
||
|
|
GPU PGD hijack -> arbitrary kernel R/W -> modify credentials -> root + setenforce 0
|
||
|
|
- Public exploit code linked directly from the GitHub Blog article
|
||
|
|
(https://github.blog/security/vulnerability-research/bypassing-mte-with-cve-2025-0072/)
|
||
|
|
- Does NOT require kernel offsets unlike CVE-2023-6241 — uses GPU page table hijack approach
|
||
|
|
- Requires hardcoded offsets to be recalculated per-build (like predecessor)
|
||
|
|
- **Window:** Pixel 7/8/9 on any ASB between May 2024 (A14 launch) and May 2025 patch
|
||
|
|
- **Android 15 relevance:** Pixel 9 launched Oct 2024; A15 shipped Nov 2024.
|
||
|
|
Any Pixel 9 on ASB < 2025-05-05 (6+ months of devices in field) is vulnerable.
|
||
|
|
|
||
|
|
### CVE-2025-48543 (Android Runtime UAF) — NEW
|
||
|
|
- **Type:** Use-after-free in Android Runtime (ART)
|
||
|
|
- **Affected:** Android 13, 14, 15, 16 — all versions
|
||
|
|
- **Access required:** Malicious app (no special privileges, no ADB required)
|
||
|
|
- **Achieves:** System process-level access (system UID), sandbox escape
|
||
|
|
- **CVSS:** 8.8 HIGH (local, no interaction, scope change — full impact)
|
||
|
|
- **Patched:** September 2025 ASB (2025-09-05)
|
||
|
|
- **PoC:** https://github.com/gamesarchive/CVE-2025-48543 (C++ PoC, quality unknown)
|
||
|
|
- **Window:** All devices with ASB < 2025-09-05 — significant field population
|
||
|
|
- **Chain potential:** App exec -> UAF -> system UID -> disable Play Integrity / MDM
|
||
|
|
|
||
|
|
### CVE-2025-48572 + CVE-2025-48633 (Framework zero-days, in-the-wild) — NEW
|
||
|
|
- **Type:** CVE-2025-48633 = info disclosure (memory contents); CVE-2025-48572 = EoP
|
||
|
|
- **Affected:** Android 13, 14, 15, 16
|
||
|
|
- **Access required:** Malicious app
|
||
|
|
- **Chain:** CVE-2025-48633 leaks sensitive memory -> CVE-2025-48572 uses leak for
|
||
|
|
controlled privilege escalation -> admin-level control
|
||
|
|
- **Exploitation status:** CONFIRMED in-the-wild by Google Dec 2025; CISA KEV catalog
|
||
|
|
- **Attribution hint:** "Limited, targeted exploitation" language = likely state-sponsored
|
||
|
|
- **Patched:** December 2025 ASB (2025-12-05)
|
||
|
|
- **PoC:** No public PoC — actively exploited tools held by threat actors
|
||
|
|
- **Window:** All devices with ASB < 2025-12-05
|
||
|
|
- **Component:** Android Framework (exact class not disclosed as of 2026-03)
|
||
|
|
|
||
|
|
### CVE-2025-38352 (Kernel POSIX timer TOCTOU) — USABLE ON PIXEL 6 ONLY
|
||
|
|
- **Type:** TOCTOU race condition in handle_posix_cpu_timers()
|
||
|
|
- **Kernel target:** GKI 5.10.x (Linux) — Pixel 6 series ONLY among Pixels
|
||
|
|
- **Exploit:** Chronomaly by farazsth98 — https://github.com/farazsth98/chronomaly
|
||
|
|
- x86_64 only in published form (but vulnerability is architecture-independent)
|
||
|
|
- Requires CONFIG_POSIX_CPU_TIMERS_TASK_WORK=n kernel config
|
||
|
|
- Chain: UAF -> cross-cache reallocation -> pipe buffer hijack -> cred modification
|
||
|
|
- **NOT confirmed** on GKI 5.15 (Pixel 7/8) or GKI 6.1 (Pixel 9)
|
||
|
|
- **Patched:** September 2025 ASB
|
||
|
|
- **Exploitation in wild:** Google confirmed limited targeted attacks
|
||
|
|
|
||
|
|
### fastboot boot — CONFIRMED WORKS ON ANDROID 15/16
|
||
|
|
- init_boot.img patching with Magisk works on Android 15 and 16 on all Pixels
|
||
|
|
- All Pixel 6 and later use init_boot.img (not boot.img) for Magisk
|
||
|
|
- KernelSU-Next / SukiSU-Ultra: official support for GKI 6.1 (Pixel 9) and 6.6 (Pixel 9a)
|
||
|
|
- APatch: also supports GKI 6.1/6.6 via kpatch binary method
|
||
|
|
- `fastboot boot` temporary boot still works (does not flash permanently)
|
||
|
|
- Command unchanged: `fastboot boot magisk_patched_init_boot.img`
|
||
|
|
- **avbroot workflow (for relocked bootloader with root):**
|
||
|
|
1. Generate custom AVB key pair (avbroot keygen)
|
||
|
|
2. Patch OTA zip: `avbroot ota patch --input ota.zip --key-avb avb.key --prepatched kernelsu.img`
|
||
|
|
3. Flash patched OTA via `adb sideload` or fastboot
|
||
|
|
4. `fastboot flash avb_custom_key avb_pkmd.bin`
|
||
|
|
5. `fastboot flashing lock` (triggers wipe — do last)
|
||
|
|
6. Result: locked bootloader, Verified Boot using custom key, KernelSU root active
|
||
|
|
- Survives OTA updates if patched OTA is sideloaded
|
||
|
|
- Works on Pixel 4+ (AVB 2.0), confirmed working approach on Pixel 9
|
||
|
|
|
||
|
|
### ADB Shell (UID 2000) on Android 15/16 — CAPABILITIES UNCHANGED
|
||
|
|
- WRITE_SECURE_SETTINGS: still granted to shell
|
||
|
|
- INSTALL_PACKAGES: still granted
|
||
|
|
- READ_LOGS: still granted
|
||
|
|
- pm, am, settings commands: all functional
|
||
|
|
- **Key change:** CVE-2024-31317 Zygote injection is patched (14 QPR2 / March 2024 ASB)
|
||
|
|
No confirmed replacement for arbitrary app UID escalation from shell on Android 15
|
||
|
|
- **Best approach on Android 15/16 from shell:** CVE-2025-0072 if on old ASB, or
|
||
|
|
CVE-2025-48543/CVE-2025-48572 if on ASB < their respective patch levels
|
||
|
|
|
||
|
|
### pKVM bugs (CVE-2025-48623, CVE-2026-0037 cluster) — CONTEXT-DEPENDENT
|
||
|
|
- Affect Android 15/16 kernel pKVM subsystem
|
||
|
|
- Critical severity (CVSS 9.0 for CVE-2026-0037)
|
||
|
|
- **Prerequisite:** Require existing System execution privileges to exploit further
|
||
|
|
- Not directly exploitable from ADB shell or unprivileged app alone
|
||
|
|
- Useful as second-stage escalation: app -> system (via CVE-2025-48543) -> pKVM -> hypervisor
|
||
|
|
- No public PoC — patched Dec 2025 and Mar 2026 ASBs
|
||
|
|
|
||
|
|
### CVE-2026-21385 (Qualcomm display driver) — NOT APPLICABLE TO PIXEL 7/8/9
|
||
|
|
- Affects 235 Qualcomm chipsets; exploited in wild as of March 2026
|
||
|
|
- Pixel 7/8/9 use Google Tensor (Mali GPU) — NOT Qualcomm — so this is irrelevant
|
||
|
|
- Relevant for Samsung Galaxy, Motorola, OnePlus, Xiaomi with Snapdragon chipsets
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## ANDROID VERSION EXPLOIT MATRIX (updated 2026-03-03)
|
||
|
|
|
||
|
|
| CVE | A12 | A13 | A14 | A15 | A16 | PoC Available |
|
||
|
|
|-----|-----|-----|-----|-----|-----|---------------|
|
||
|
|
| CVE-2024-0044 | YES | YES | Partial | NO | NO | YES (public) |
|
||
|
|
| CVE-2024-31317 | YES | YES | YES | NO | NO | YES (writeup+PoC) |
|
||
|
|
| CVE-2023-6241 (Mali) | - | - | YES (Oct/Nov ASB) | - | - | YES (public) |
|
||
|
|
| CVE-2025-0072 (Mali CSF) | - | - | YES | YES | YES* | YES (GitHub PoC) |
|
||
|
|
| CVE-2025-48543 (ART UAF) | - | YES | YES | YES | YES | YES (C++ PoC) |
|
||
|
|
| CVE-2025-48572 (Framework EoP) | - | YES | YES | YES | YES | NO (ITW) |
|
||
|
|
| CVE-2025-48633 (Framework ID) | - | YES | YES | YES | YES | NO (ITW) |
|
||
|
|
| CVE-2025-38352 (kernel timer) | YES | YES | YES | YES | - | YES (5.10.x only) |
|
||
|
|
| CVE-2023-21400 (io_uring) | YES | YES | ? | NO | NO | Research only |
|
||
|
|
| CVE-2023-20938 (Binder) | YES | YES | NO | NO | NO | No public |
|
||
|
|
| CVE-2024-53104 (UVC) | YES | YES | YES | YES | YES | Post-patch PoC |
|
||
|
|
| CVE-2024-32896 (Pixel FW) | - | - | YES | NO | NO | No public |
|
||
|
|
| CVE-2024-43093 (Framework) | YES | YES | YES | YES | - | No public |
|
||
|
|
|
||
|
|
*CVE-2025-0072 on A16 (Pixel 9a): depends on shipping ASB; needs verification.
|
||
|
|
A16 is very new and patch status in field likely current.
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## RECOMMENDED AUTARCH EXPLOIT CHAIN FOR PIXEL 6/7/8 (Android 12-14)
|
||
|
|
|
||
|
|
**Goal: Read arbitrary app data from ADB shell (UID 2000)**
|
||
|
|
|
||
|
|
1. Check Android version + ASB via `getprop ro.build.version.security_patch`
|
||
|
|
2. If Android 12/13 unpatched (pre-March 2024): CVE-2024-0044 directly
|
||
|
|
3. If Android 12-14 unpatched (pre-March 2024): CVE-2024-31317 via WRITE_SECURE_SETTINGS
|
||
|
|
4. If Android 14 (Oct/Nov 2023 ASB) on Pixel 7/8: Pixel_GPU_Exploit (CVE-2023-6241)
|
||
|
|
5. For Mali-equipped devices on older ASBs: chain info-leak + integer overflow
|
||
|
|
|
||
|
|
**Goal: Temporary root with bootloader unlock**
|
||
|
|
|
||
|
|
1. `fastboot boot magisk_patched_init_boot.img`
|
||
|
|
2. Inside rooted boot: extract data, disable SELinux (`setenforce 0`), persist if needed
|
||
|
|
3. Reboot to stock — no permanent change to device flash
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## RECOMMENDED AUTARCH EXPLOIT CHAIN FOR PIXEL 8/9 (Android 15/16)
|
||
|
|
|
||
|
|
**Goal: Kernel root from untrusted app, no bootloader unlock**
|
||
|
|
|
||
|
|
Prerequisite check (run via ADB before selecting path):
|
||
|
|
```sh
|
||
|
|
getprop ro.build.version.release # Android major version
|
||
|
|
getprop ro.build.version.security_patch # YYYY-MM-DD
|
||
|
|
getprop ro.hardware.chiptype # tensor / qcom
|
||
|
|
```
|
||
|
|
|
||
|
|
Path A — CVE-2025-0072 (Mali CSF UAF), ASB < 2025-05-05, Pixel 7/8/9:
|
||
|
|
- Deliver exploit app via ADB or sideload
|
||
|
|
- No PoC is fully weaponized/turnkey; requires port of GitHub Blog PoC + kernel offset calculation
|
||
|
|
- Full chain: app spawn -> Mali IOCTL sequence -> UAF -> PGD hijack -> kernel R/W -> root
|
||
|
|
- Reliability: MEDIUM (offset-dependent, like 0x36 predecessor)
|
||
|
|
- Stealth: LOW (kernel exploit, may trigger watchdog/audit)
|
||
|
|
|
||
|
|
Path B — CVE-2025-48543 (ART UAF), ASB < 2025-09-05, Android 13-16:
|
||
|
|
- Deliver exploit APK, trigger ART UAF from malicious app
|
||
|
|
- Achieves: system UID — useful for disabling MDM, accessing system-app data
|
||
|
|
- Does NOT directly give root, but system UID can call many privileged APIs
|
||
|
|
- PoC quality uncertain (gamesarchive repo) — may need significant weaponization
|
||
|
|
- Reliability: LOW-MEDIUM (PoC exists but untested in AUTARCH context)
|
||
|
|
|
||
|
|
Path C — fastboot boot (any Android 15/16 device with unlocked bootloader):
|
||
|
|
- `fastboot boot magisk_patched_init_boot.img` or KernelSU equivalent
|
||
|
|
- Full root achieved, SELinux can be set permissive
|
||
|
|
- Reliability: HIGH
|
||
|
|
- Stealth: LOW (bootloader unlock state is visible, triggers Play Integrity failure)
|
||
|
|
|
||
|
|
Path D — avbroot + KernelSU + relock (long-term persistent root, stealthy):
|
||
|
|
- Best for authorized assessments requiring persistent access
|
||
|
|
- Device appears to have locked bootloader to casual inspection
|
||
|
|
- Survives OS-level factory reset attempts
|
||
|
|
- Play Integrity still fails (custom AVB key not trusted by Google)
|
||
|
|
- Reliability: HIGH on Pixel 4+
|
||
|
|
- Stealth: MODERATE (DM-verity green, but Play Integrity Hardware attestation fails)
|
||
|
|
|
||
|
|
---
|
||
|
|
|
||
|
|
## KEY REFERENCES
|
||
|
|
|
||
|
|
- 0x36 GPU exploit repo: https://github.com/0x36/Pixel_GPU_Exploit
|
||
|
|
- bad_io_uring PoC: https://github.com/Markakd/bad_io_uring
|
||
|
|
- CVE-2024-0044 PoC: https://github.com/0xbinder/CVE-2024-0044
|
||
|
|
- CVE-2024-31317 writeup: https://blog.flanker017.me/cve-2024-31317/
|
||
|
|
- Binder UAF analysis: https://androidoffsec.withgoogle.com/posts/attacking-android-binder-analysis-and-exploitation-of-cve-2023-20938/
|
||
|
|
- MTE bypass (CVE-2025-0072): https://github.blog/security/vulnerability-research/bypassing-mte-with-cve-2025-0072/
|
||
|
|
- CVE-2025-48543 PoC: https://github.com/gamesarchive/CVE-2025-48543
|
||
|
|
- Chronomaly (CVE-2025-38352): https://github.com/farazsth98/chronomaly
|
||
|
|
- CVE-2025-38352 PoC: https://github.com/farazsth98/poc-CVE-2025-38352
|
||
|
|
- avbroot tool: https://github.com/chenxiaolong/avbroot
|
||
|
|
- PixelFlasher tool: https://github.com/badabing2005/PixelFlasher
|
||
|
|
- KernelSU-Next: https://github.com/KernelSU-Next/KernelSU-Next
|
||
|
|
- Linux kernel exploit list: https://github.com/xairy/linux-kernel-exploitation
|
||
|
|
- Dec 2025 ASB zero-days: https://source.android.com/docs/security/bulletin/2025-12-01
|
||
|
|
- Mar 2026 ASB: https://www.helpnetsecurity.com/2026/03/03/android-march-2026-security-patch-cve-2026-21385/
|