A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain
An article by Maddie Stone covering an exploit chain for Exynos-based Samsung phones that relies on two kernel bugs.
The exploit bypasses KASLR by triggering a warning and reading the report from the kernel log. The exploit then uses a use-after-free of the file structure in the DECON driver to gain AARW by controlling addr_limit.
Post #197
3.87K