One exploit strategy roots Samsung, Xiaomi, and Oppo flagships from an unprivileged Android app

OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others

One exploit strategy roots Samsung, Xiaomi, and Oppo flagships from an unprivileged Android app

A new research series details a generic exploitation strategy that takes an unprivileged Android app to root on Samsung, Xiaomi, and Oppo/OnePlus/Realme devices. The approach targets page use-after-free bugs in OEM-specific kernel drivers, reaching them via OEM-specific sandbox escapes where SELinux blocks direct access. By focusing on OEM code rather than generic Linux or chipset drivers, the strategy achieves reliability, portability, and broad coverage across flagship models.

The core idea is to only target code written by Original Equipment Manufacturers (OEMs) such as Samsung and Xiaomi.
  1. FrequentLurker

    I wonder if there is a vulnerability that allows for toggling wireless adb. I have an LG with android 12 which technically should support wireless ADB but LG stripped the option from settings. Some say they stripped out the feature entirely. On top of that the USB port is damaged and doesnt accept data but still accepts power. So no wired adb either.

  2. gorgmah

    Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android?

    The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

  3. _ZeD_

    will the "exploit" app be available? asking for a friend :D

  4. ece

    You'd almost think supporting a phone for a longer amount of time might actually be better than trying to sell a new phone every year or two.

  5. ArtTimeInvestor

    A good security track record must be the most valuable company asset in history.

    Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ...

    I have one too.

    Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I like the software too much. Android is much more to my liking with more freedom to customize it.

    But because I have the feeling Apple takes security more seriously.

    I wish there was some kind of security arena like there is LLM arena for AI. That gives hard facts about the security track record of phone manufacturers.

More from this day

2026-09-14