From graphics driver to root shell: a tour of Samsung’s kernel protections
ID: a032671d-f2a1-530f-a6eb-7c90bc26cd6e
STIX ID: report--a032671d-f2a1-530f-a6eb-7c90bc26cd6e
Feed Name: Jamf Blog
Threat Score
Jamf Threat Labs demonstrates how a Qualcomm KGSL/GPU DMA vulnerability (CVE-2025-21479) can bypass Samsung's EL2/hypervisor kernel protections (RKP, KDP, DEFEX, JOPP/ROPP) by performing DMA writes that do not trigger CPU Stage 2 checks, using a self-referencing page-table trick to gain fast arbitrary read/write, disabling SELinux, and injecting code into the init process to obtain persistent root on affected Galaxy devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
