cross-posted from: https://lemmy.world/post/52394317

Research shows that an app requesting no Android permissions can abuse privileged OxygenOS components and eventually reach root. The exploit chain involves AtlasService and the olc2 vendor HAL, effectively taking an app that should be heavily sandboxed and giving it access to much more privileged functionality.

It also highlights a broader problem with Android OEM security. AOSP gets a lot of scrutiny, but manufacturers add their own services, Binder interfaces and vendor components on top of it. A single mistake in one of those privileged components can undermine a lot of the protections underneath.