STAR Labs detailed two exploit chains showing how vulnerabilities in the Arm Mali GPU driver could be turned into full kernel compromise on Google Pixel phones. One write-up analyzed CVE-2023-6241, a race condition in kbase_jit_grow on a Pixel 8 running Android 14, where stale allocation state after a lock drop left some physical pages backed but unmapped. That inconsistency was used to trigger a page use-after-free, reclaim the freed page, and build arbitrary kernel read/write primitives. The exploit then overwrote kernel code to disable SELinux enforcement and invoked commit_creds(&init_cred) to gain root from the unprivileged untrusted_app_27 context; STAR Labs said excessive WARN_ON logging initially stretched exploitation to about 10 minutes before testing reduced runtime to under five seconds.
A second write-up showed that CVE-2023-48409 alone was sufficient to compromise a Pixel 6 Pro, contradicting earlier assumptions that exploitation also required CVE-2023-26083. STAR Labs described the bug as an integer-overflow-driven out-of-bounds write in the Pixel Mali driver and said exploitation bypassed CONFIG_HARDENED_USERCOPY by targeting page-allocator-backed objects and using pagetable spraying techniques inspired by Dirty Pagetable. The researchers also mapped Android-specific constraints including seccomp, SELinux, and privilege-escalation mechanics, and found that while the earlier pointer-leak bug still existed on affected devices, the practical path relied on leaking a kbase_context object exposing a task_struct pointer for direct credential manipulation. Both reports said the affected issues were patched in later Android security updates.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published a write-up showing that CVE-2023-48409 by itself was sufficient to compromise a Pixel 6 Pro, contrary to prior assumptions that CVE-2023-26083 was also required. The analysis identified kbase_context as an alternative leaked object exposing a task_struct pointer, enabling direct credential manipulation.
STAR Labs published a technical write-up detailing exploitation of CVE-2023-6241 on a Google Pixel 8 running Android 14, including methods to reclaim freed pages and obtain root privileges. The write-up also noted that suppressing WARN_ON logging reduced exploit runtime from about 10 minutes to under 5 seconds.
A patch was issued for CVE-2023-6241 that rechecked whether memory growth was still needed after the race window and recalculated old_size and delta using the current reg->gpu_alloc->nents value. This addressed the stale-state condition in kbase_jit_grow.
STAR Labs published a technical analysis of Mali GPU driver vulnerabilities CVE-2022-22706 and CVE-2021-39793, showing how improper permission checks could let an unprivileged Android app gain a powerful write primitive and escalate to root. The write-up demonstrated a full exploit chain on a Pixel 6 running Android 12, including hijacking privileged processes, disabling SELinux, and obtaining a root shell.
Google's December 2023 security patch level fixed the Pixel Mali GPU vulnerabilities CVE-2023-48409 and CVE-2023-26083. Before that patch level, a Pixel 6 Pro remained vulnerable to an exploit chain that could achieve kernel read/write and root.
A race condition in the Mali GPU driver's kbase_jit_grow function left some physical pages backed but unmapped on Google Pixel 8 devices running Android 14 before the fix. The flaw could be exploited to create a page use-after-free and ultimately gain arbitrary kernel read/write.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.