Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

TiYunZong Exploit Chain to Remotely Root Modern Android Devices - Pwn Android Phones from 2015-2020

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This advanced presentation analyzes the TiYunZong exploit chain for remotely compromising Qualcomm-based Android devices, including Pixel phones. It examines three vulnerabilities across Chrome, Android IPC, and the GPU driver, then demonstrates obtaining a root shell.

Syllabus

Intro
Why Google Pixel Phone Is A Tough Target
Remote Attack Surface of Smart Phones
Experience of Pwning Android Devices
The Exploit Chain(TiYunZong)
Torque in Chrome v8
JSFunction Memory Layout
The Bug(CVE-2019-5877)
Trigger the Bug
How to Exploit
Exploit Strategy
Chrome' s Multi-Process Architecture
The Mojo Interface Definition of Content Decryption Module (CDM)
The Implementation of the Initialized Function of CDM
The Fucntion RegisterCdm
Trigger UAF
Exploit the ERP Bug
The Format of the Scratch Memory
Where is the Bug
of a Ring Buffer
Read And Write Pointer
Allocate Space From Ring Buffer
Overwrite Exist Instructions
CP Instruction Sequence of Executing IOCTL_KGSL GPU COMMAND
The Process of Exploiting CVE-2019-10567
Demo

Taught by

Black Hat

Reviews

Start your review of TiYunZong Exploit Chain to Remotely Root Modern Android Devices - Pwn Android Phones from 2015-2020

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.