Tile-Based Deferred Rooting: When Your GPU Starts Rendering To Kernel Code Space!

Xingyu Jin, Martijn Bogaard

OffensiveCon 2026 · Day 1 · Main Stage

This talk, presented by Xingyu Jin and Martijn Bogaard, delves into a fascinating and unconventional GPU hardware vulnerability discovered during the development of the Google Pixel 10. The researchers, part of the Android threat team, uncovered a critical flaw in the **Imagination Technologies PowerVR GPU** (DXT generation) that allowed an untrusted application to overwrite Linux kernel code and achieve root privileges. The presentation highlights the intricate process of black-box reverse engineering GPU hardware behavior and the creative exploitation techniques required to leverage such a primitive against a modern Android kernel.

AI review

Jin and Bogaard weaponize a GPU hardware misconfiguration into a full Android kernel root — CVE-2023-28509 on PowerVR's TBDR architecture — through black-box reverse engineering of undocumented parameter manager behavior, progressive primitive refinement, and a multi-stage mitigation bypass chain. This is original, deep, pre-release work on a class of attack surface most researchers haven't touched, and the exploitation path is genuinely novel.

Watch on YouTube