Researcher Lukas Maar disclosed OEMPocalypse, a cross-OEM Android privilege-escalation technique targeting manufacturer-added kernel components in Samsung One UI, Xiaomi HyperOS, and Oppo ColorOS rather than generic Linux kernel flaws or chipset drivers.

The chains exploit page use-after-free in OEM kernel drivers and, when SELinux restricts driver access, first use an OEM sandbox escape from untrusted_app. A stale mapping to a freed physical page provides page-level kernel-memory access without KASLR disclosure or control-flow hijacking.

Demonstrated on stock, locked-bootloader devices with July 2026 firmware: Galaxy S26 Ultra, Galaxy S26, Xiaomi 17, Oppo Find X9 Ultra, and OnePlus Ace 6 Ultra. Page-reclamation code worked unchanged on Linux kernels 5.15 through 6.12.