Pwning the all Google phone with a non-Google bug
It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.
Discussion around the web
- Hacker News245 · 94 💬
Score breakdown
- Technical depth85
- Practical value60
- Originality85
- Writing quality82
- Source reputation85
- Recency0
- External engagement34
- On-site engagement0
More like this
The Cloudflare Blog68
How we found a bug in Go's arm64 compiler
unknown·22 min read
The Cloudflare Blog55
A closer look at a BGP anomaly in Venezuela
unknown·16 min read
Stripe Engineering52
Root cause analysis: significantly elevated error rates on 2019‑07‑10
unknown·10 min read
Engineering at Meta63
Reverse debugging at scale
unknown·9 min read
Engradar shows a summary and links to the original article. The full article is hosted on github.blog.