Back to feed

Researcher shows unprivileged app gains root on Samsung, Xiaomi, Oppo flagships

1 min
Researcher shows unprivileged app gains root on Samsung, Xiaomi, Oppo flagships

This digest was compiled by AI from multiple sources — links to the originals are below.

Security researcher Lukas Maar demonstrated an unprivileged Android app gaining root access on flagship phones from Samsung, Xiaomi, Oppo, OnePlus, and Realme. The exploit chains, dubbed OEMpocalypse Now, target vulnerabilities in manufacturer-added software and drivers rather than stock Android. The researcher withheld proof-of-concept code and shared only video evidence.

Key Facts

  • Lukas Maar, a security researcher at Calif, demonstrated an unprivileged app with no permissions taking full control of Android devices from Samsung, Xiaomi, Oppo, OnePlus, and Realme.
  • The exploit chains, dubbed OEMpocalypse Now, target vulnerabilities in manufacturer-added software and drivers, not stock Android itself.
  • The attack first escapes the app sandbox, then abuses a memory flaw in an OEM kernel driver to achieve root access.
  • The researcher did not reveal the proof-of-concept code and only shared several video clips as evidence of hacking flagship smartphones.

Affected Devices

The exploits affected Samsung flagships from at least the Galaxy S23 through the S26 series and the recent Z series, most Xiaomi mid-range to flagship devices, and recent Oppo, OnePlus, and Realme flagships. The vulnerabilities were not tied to a specific Android version, chipset, kernel version, or device model. Many smartphones run the same flawed additional software layer, such as One UI, HyperOS, or ColorOS, with OEM-specific kernel drivers.

Exploit Mechanism

Third-party Android apps normally run in a sandboxed context called untrusted_app and cannot talk to kernel drivers directly. Maar describes an untrusted_app-to-root exploit that reportedly achieves near-100% reliability regardless of Android defenses or customizations. The exploit is implemented in two major stages: first a sandbox escape, then abuse of a memory flaw in an OEM kernel driver. Root access grants attackers near-complete control over the device and its data, bypassing Android's permission model and potentially causing hardware damage.

1 source

Time · lag behind first