Researcher Lukas Maar disclosed OEMPocalypse, a cross-OEM Android privilege-escalation technique targeting manufacturer-added kernel components rather than generic Linux kernel flaws or chipset drivers. The chains exploit a page use-after-free in an OEM kernel driver and, when SELinux restricts driver access, first use an OEM sandbox escape. A stale mapping to a freed physical page is then reclaimed to obtain page-level kernel-memory access and kernel-level compromise.
The technique reportedly avoids both a KASLR information disclosure and control-flow hijacking, limiting the effectiveness of several slab-allocation and CFI hardening measures. Its page-reclamation method was reported to function unchanged on Linux kernels 5.15 through 6.12, with tailored chains demonstrated against Samsung, Xiaomi, and Oppo software stacks on stock, locked-bootloader Galaxy S26 Ultra, Galaxy S26, Xiaomi 17, Oppo Find X9 Ultra, and OnePlus Ace 6 Ultra devices running July 2026 firmware.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Lukas Maar published the first OEMpocalypse research installment, describing an optional logical flaw in OEM IPC endpoints to escape the untrusted_app domain followed by a page use-after-free in OEM kernel drivers for physical-memory read/write. The report included testing on locked-bootloader stock devices, including Samsung, Xiaomi, Oppo, and OnePlus models across Android 14 and 16.
Lukas Maar presented OEMPocalypse, separate Android exploit chains targeting OEM kernel components in Samsung One UI, Xiaomi HyperOS, and Oppo ColorOS. The chains reportedly achieved root-level compromise on five stock, locked-bootloader devices using July 2026 firmware, leveraging OEM sandbox escapes where needed and page use-after-free flaws in OEM drivers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcemalware.news
Open sourceblog.calif.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.