{"id":16645,"date":"2023-01-24T16:33:07","date_gmt":"2023-01-24T15:33:07","guid":{"rendered":"https:\/\/www.show.it\/arm-vulnerability-leads-to-code-execution-root-on-pixel-6-phones\/"},"modified":"2023-01-24T16:33:07","modified_gmt":"2023-01-24T15:33:07","slug":"arm-vulnerability-leads-to-code-execution-root-on-pixel-6-phones","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/arm-vulnerability-leads-to-code-execution-root-on-pixel-6-phones\/","title":{"rendered":"Arm Vulnerability Leads to Code Execution, Root on Pixel 6 Phones"},"content":{"rendered":"<p><strong>A security researcher has published technical details on an Arm Mali GPU vulnerability leading to arbitrary kernel code execution and root on Pixel 6 phones using a malicious app installed on the targeted device.<\/strong><\/p>\n<p>Tracked as CVE-2022-38181 (CVSS score of 8.8), the issue is described as a use-after-free bug that impacts<a href=\"https:\/\/developer.arm.com\/downloads\/-\/mali-drivers\/valhall-kernel\" target=\"_blank\" rel=\"noreferrer noopener\"> Arm Mali GPU driver versions<\/a> prior to r40p0 (released on October 7, 2022).<\/p>\n<p>The issue, GitHub Security Lab researcher Man Yue Mo explains, is related to a special function for sending \u2018job chains\u2019 to the GPU, but which also supports jobs implemented in the kernel, which run on the CPU instead (and which are called software jobs or softjobs).<\/p>\n<p>\u201cDue to the complexity involved in managing memory sharing between user space applications and the GPU, many of the vulnerabilities in the Arm Mali GPU involve the memory management code. The current vulnerability is another example of this, and involves a special type of GPU memory: the JIT memory,\u201d Man Yue Mo notes in a<a href=\"https:\/\/github.blog\/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug\/\" target=\"_blank\" rel=\"noreferrer noopener\"> detailed technical description<\/a> of the vulnerability.<\/p>\n<p>Some of the softjobs instruct the kernel to allocate and free JIT memory, and CVE-2022-38181 is related to these: malicious code can be used to add a JIT memory region to an eviction list, then create memory pressure to trigger a vulnerable eviction function, resulting in the JIT region being freed without freeing the pointer.<\/p>\n<p>What the researcher discovered was that a freed JIT region could be replaced with a fake object, which could be used to potentially free arbitrary pages and then exploit these to gain read and write access to arbitrary memory.<\/p>\n<p>As a final step in exploiting the vulnerability, an attacker would need to \u201cmap kernel code to the GPU address space to gain arbitrary kernel code execution, which can then be used to rewrite the credentials of our process to gain root, and to disable SELinux,\u201d the researcher says.<\/p>\n<p>Man Yue Mo reported the vulnerability to the Android security team in July 2022, along with proof-of-concept (PoC) code demonstrating how the issue can be exploited to execute code and gain root access on Pixel 6.<\/p>\n<p>Initially, the Android team marked the flaw \u2018high severity\u2019, but it then informed the researcher that no patch will be released and redirected the report to the Arm team.<\/p>\n<p>After Arm\u2019s patch in October 2022, Google included a fix for this vulnerability in<a href=\"https:\/\/www.securityweek.com\/androids-first-security-updates-2023-patch-60-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\"> the January 2023 security update<\/a> for Pixel devices, but without mentioning the CVE ID or the original bug IDs, the researcher says.<\/p>\n<p><strong>Related:<a href=\"https:\/\/www.securityweek.com\/over-75-vulnerabilities-patched-android-december-2022-security-updates\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Over 75 Vulnerabilities Patched in Android With December 2022 Security Updates<\/a><\/strong><\/p>\n<p><strong>Related:<a href=\"https:\/\/www.securityweek.com\/google-migrating-android-memory-safe-programming-languages\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Google Migrating Android to Memory-Safe Programming Languages<\/a><\/strong><\/p>\n<p><strong>Related:<a href=\"https:\/\/www.securityweek.com\/vulnerabilities-popular-keyboard-and-mouse-android-apps-expose-user-data\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Vulnerabilities in Popular Keyboard and Mouse Android Apps Expose User Data<\/a><\/strong><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/arm-vulnerability-leads-to-code-execution-root-on-pixel-6-phones\/\">Arm Vulnerability Leads to Code Execution, Root on Pixel 6 Phones<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/\">SecurityWeek<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A security researcher has published technical details on an Arm Mali GPU vulnerability leading to arbitrary kernel code execution and root on Pixel 6 phones using a malicious app installed on the targeted device. Tracked as CVE-2022-38181 (CVSS score of 8.8), the issue is described as a use-after-free bug that impacts Arm Mali GPU driver [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16646,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[48,83,23,73],"tags":[],"class_list":["post-16645","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile-wireless","category-pixel","category-vulnerabilities","category-vulnerability"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16645","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=16645"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16645\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media\/16646"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=16645"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=16645"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=16645"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}