The GitHub Blog·unknown·34 min read·Man Yue Mo63

Gaining kernel code execution on an MTE-enabled Pixel 8

In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulnerability can be exploited even when Memory Tagging Extension (MTE), a powerful mitigation, is enabled on the device.

Discussion around the web

Score breakdown

  • Technical depth86
  • Practical value60
  • Originality85
  • Writing quality82
  • Source reputation85
  • Recency0
  • External engagement34
  • On-site engagement0

More like this

Engradar shows a summary and links to the original article. The full article is hosted on github.blog.