OEMpocalypse Now: A Generic Exploitation Strategy from Android untrusted app to root
- Part 1 of a series that takes an unprivileged Android app to root on Samsung, Xiaomi, and Oppo/OnePlus/Realme devices, with a single strategy.
- On Android, every third-party app runs in a sandboxed context called untrusted_app.
- If you ask five offensive security researchers how to go from this context to root, you will most likely get five different strategies, and each has its own trade-offs.
Unverified
- Part 1 of a series that takes an unprivileged Android app to root on Samsung, Xiaomi, and Oppo/OnePlus/Realme devices, with a single strategy.
- On Android, every third-party app runs in a sandboxed context called untrusted_app.
- If you ask five offensive security researchers how to go from this context to root, you will most likely get five different strategies, and each has its own trade-offs.
Sources: Calif