From Zero To Root: Attacking Qualcomm DSP Driver

Xiling Gong

OffensiveCon 2026 · Day 1 · Main Stage

This talk by Xiling Gong from Tencent Blade Team delves into a critical vulnerability (CVE-2023-47394) found within the second generation of Qualcomm's **FastRPC** driver, a core component responsible for interfacing with the **Audio/Application Digital Signal Processor (ADSP)**. The presentation meticulously details a complex, multi-stage exploit chain that leverages this vulnerability to achieve root privileges from an untrusted Android application. This research is particularly significant as it targets a highly privileged and often overlooked component of modern System-on-Chips (SoCs), demonstrating how even after substantial security improvements, complex drivers can harbor exploitable flaws.

AI review

Xiling Gong delivers a genuine technical masterclass: original vulnerability discovery in a hardened Gen2 driver, a full exploit chain against a live flagship device, and a methodical walkthrough of bypassing every major modern kernel mitigation. This is exactly the kind of work OffensiveCon exists to showcase — hard-won, deeply skilled, and impossible to fake.

Watch on YouTube