March 20, 2024, 5:28 p.m. | Black Hat

Black Hat www.youtube.com

...In this talk, we will demonstrate vulnerabilities in the Imagination Technologies' PowerVR GPU, which is used in a wide range of Android devices. We have discovered several physical page UAF vulnerabilities, most of which are caused by the mishandled sparse texture memory management. Specifically, a malicious actor can manipulate arbitrary freed physical pages from the CPU side using OpenGL or from the GPU side using OpenCL. Unlike typical device driver exploits which heavily rely on driver IOCTL calls, a malicious …

android android devices apis devices exploit gpu imagination kernel management memory page physical technologies uaf vulnerabilities

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Staff Firmware Engineer – Networking & Firewall

@ Axiado | Bengaluru, India

Compliance Architect / Product Security Sr. Engineer/Expert (f/m/d)

@ SAP | Walldorf, DE, 69190

SAP Security Administrator

@ FARO Technologies | EMEA-Portugal