Dispatch
Calif.io's OEMpocalypse chains one strategy from an unprivileged Android app to root on Samsung, Xiaomi and Oppo flagships
The research chains a logic flaw in OEM IPC endpoints to escape the SELinux untrusted_app domain into a privileged OEM process, then triggers a page use-after-free in OEM-specific kernel drivers for arbitrary physical-memory read/write and root. The exploits ran on a Galaxy S26 Ultra, Galaxy S26, Xiaomi 17, Oppo Find X9 Ultra and OnePlus Ace 6 Ultra, all on stock July 2026 firmware with locked bootloaders and verified boot. Samsung's 8 September patch fixed 90 issues but does not list CVE-2026-43499, and Xiaomi and Oppo have said nothing, so the interesting part for builders is that the bug class lives in vendor add-on code (One UI, HyperOS, ColorOS) rather than AOSP.
↳ Follow the thread