Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world

OnePlus 15 Root Exploit: Zero-Permission App Escapes Android Sandbox

cross-posted from: https://lemmy.world/post/52394319

cross-posted from: https://lemmy.world/post/52394317

Research shows that an app requesting no Android permissions can abuse privileged OxygenOS components and eventually reach root. The exploit chain involves AtlasService and the olc2 vendor HAL, effectively taking an app that should be heavily sandboxed and giving it access to much more privileged functionality.

It also highlights a broader problem with Android OEM security. AOSP gets a lot of scrutiny, but manufacturers add their own services, Binder interfaces and vendor components on top of it. A single mistake in one of those privileged components can undermine a lot of the protections underneath.

OnePlus 15 Root Exploit: Zero-Permission App Escapes Android Sandboxhttps://thecybersecguru.com/news/oneplus-15-zero-permission-root-exploit/Open linkView original on lemmy.world
34

No replies yet

No comments on the original post yet.