TGViewer
mhmrdd mhmrdd @mhm72dd · 6.41K subscribers
Post #312 2.75K
I managed to internally use HeapSnitch (modified) vulnerability in QSEE to extract UDS
As you may know Google has previously revoked this, but they reincarnated it again, and during my experiments, i figured that BCC it had did NOT involve TME or CE, and was self signed, and placed directly for S-EL0 signing.
This is critical, we expected at least that it's a leaf derivation from TME.
MediaTek claims spot 2 now that NSW-EL0 can do this on QSEE.
This came as a challenge because I've been rumored that some managed to do the same and even for StrongBox.
  • 🔥 24
  • ❤ 4
  • 👍 1
More from @mhm72dd
  1. Oct 7, 2026https://x.com/0xor0ne/status/2107848947557355769
  2. Sep 29, 2026HeapSnitch>> med sev?
  3. Sep 29, 2026video post
  4. Sep 29, 2026Update: -Adapted HeapSnitch to work on post-boot after vold CE storage decryption is compl…
  5. Sep 27, 2026photo post
  6. Sep 27, 2026https://mia-ai.net/experiments/let-there-be.html
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →