logo

From graphics driver to root shell: a tour of Samsung’s kernel protections

ID: a032671d-f2a1-530f-a6eb-7c90bc26cd6e

STIX ID: report--a032671d-f2a1-530f-a6eb-7c90bc26cd6e

Feed Name: Jamf Blog

Threat Score
85/100

Date Published: 2026-07-29

Date Updated: 2026-07-30

...
...

Jamf Threat Labs demonstrates how a Qualcomm KGSL/GPU DMA vulnerability (CVE-2025-21479) can bypass Samsung's EL2/hypervisor kernel protections (RKP, KDP, DEFEX, JOPP/ROPP) by performing DMA writes that do not trigger CPU Stage 2 checks, using a self-referencing page-table trick to gain fast arbitrary read/write, disabling SELinux, and injecting code into the init process to obtain persistent root on affected Galaxy devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.