A complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel. It does not involve memory corruptions or race conditions, so attackers don’t need to perform complex heap spraying or bypass mitigations against memory corruption vulnerabilities such as KASLR, MTE or CFI, making this exploit chain a 100% success rate on vulnerable devices.

Tested on Pixel 10 running the initial Android 17 official release. Note that it does not work on Pixel 6a and this issue may also occur on other devices running 6.1.xxx-android14 kernel trees due to another bug in these kernels.

The following is copied from our repo https://github.com/LSPosed/LSPromise for backup purposes. For more info such as PoC code, please check the original repo.

由于频道被封,整理一下还算有用的内容发到这里来。偏技术向闲聊,发布一些随谈、碎碎念或短篇/价值密度不高等我觉得不适合专门写一篇博客但仍然有留下来的价值的内容,包括但不限于编程想法、系统内部解构、人生感悟等。
有挺多人好奇我的人生经历(见 #303),比如我在我的领域是怎么起步的,还有我作为一个厌学、走职业教育路的差生的故事(#88 #303),这里一并留下来。
部分我觉得现在没什么用的内容比如纯情感发泄和线下贴贴就不再留着了。另外考虑到这里偏正式,部分条目有修改。
本频道任何消息均不构成医学建议。