Calif researcher Lukas Maar pursued how to turn a normal Android app into root access across as many phones as possible without rewriting the exploit for every model. The strategy targets OEM code — One UI, HyperOS, ColorOS — spanning lineups regardless of chipset.
The approach chains an OEM sandbox escape (when SELinux gates the target driver) with a page UAF in an OEM-specific kernel driver. Stale mappings to freed physical pages bypass KASLR, CFI, and slab hardening without control-flow hijacking.
Three instantiations cover Samsung flagships (Galaxy S23–S26, Z series), Xiaomi mid-range to flagship devices, and Oppo/OnePlus/Realme flagships. Demo videos show exploits on Galaxy S26 Ultra, Galaxy S26, Xiaomi 17, Oppo Find X9 Ultra, and OnePlus Ace 6 Ultra on stock July 2026 firmware with locked bootloaders. Parts 2–4 will detail OEM-specific bugs.