OEMpocalypse: Unprivileged Android app to root on Samsung, Xiaomi, others
A vulnerability in Android's OEM-specific code allows unprivileged apps to gain root access on Samsung, Xiaomi, and other devices. Researchers from California-based security firm, Cali, discovered the issue and have published a report detailing the vulnerability. The flaw, dubbed 'OEMpocalypse,' affects several Android devices from multiple manufacturers, including Samsung, Xiaomi, and Sony, as well as some Huawei and Oppo devices. The vulnerability allows an attacker to exploit a set of flaws in the OEM-specific code, which is used to customize Android for each device. This code is not subject to the same level of scrutiny as the main Android codebase, making it more vulnerable to security flaws. The researchers were able to develop an app that can exploit the vulnerability and gain root access on affected devices without requiring any special permissions. The researchers have made their findings public and have notified the affected manufacturers. The vulnerability affects devices running Android 10 and above, and the researchers are urging users to be cautious when installing apps from untrusted sources.
Read the full article at calif.io →