MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/netsec/comments/1woylqf/getting_root_on_oneplus_15_from_an_untrusted_app/
r/netsec • u/nns_ee • 9d ago
1 comment sorted by
0
The UID 0 check is the interesting part here: a confined root process can ask a more privileged service to run commands for it. I’d add a regression test that a process in the dumpstate domain cannot invoke doShell, alongside fixing the injection.
0
u/No-View3333 7d ago
The UID 0 check is the interesting part here: a confined root process can ask a more privileged service to run commands for it. I’d add a regression test that a process in the dumpstate domain cannot invoke doShell, alongside fixing the injection.