logo

Driving forward in Android drivers

ID: 940094fd-ec5e-5dcf-b238-d00ca3ccc8ed

STIX ID: report--940094fd-ec5e-5dcf-b238-d00ca3ccc8ed

Feed Name: Google Project Zero

Threat Score
75/100

Date Published: 2024-06-13

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Project Zero presents a technical analysis of multiple security flaws in Android third-party kernel drivers—chiefly MediaTek's JPEG decoding accelerator and the GED GPU extension—detailing two tracked CVEs (an OOB read/write and a race-induced use‑after‑free), an exploit chain that reclaims dmabuf objects via GED heap primitives to obtain arbitrary read/write, and a proof-of-concept that achieves root on tested MediaTek devices; the report also highlights inconsistent patch propagation to OEMs and recommends faster driver updates and mitigation strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.