The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel Vulnerabilities

Lukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García, Stefan Mangard

34th USENIX Security Symposium · Day 1

This groundbreaking paper, "The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel Vulnerabilities," presented by Lukas Maar and his colleagues from Graz University of Technology, critically re-evaluates the security posture of Android devices. Historically, sophisticated Android attacks necessitated complex exploit chains, often requiring initial privilege escalation within user-space before targeting the kernel. Recent trends, however, have seen attackers directly targeting kernel GPU drivers from untrusted applications, bypassing the need for these intermediate privilege pivots. While significant industry efforts, particularly from Google, have focused on hardening GPU drivers, the broader landscape of kernel drivers accessible to untrusted apps has remained largely underexplored at scale.

AI review

Solid empirical work that quantifies what many suspected but nobody had measured at scale: Android's n-day problem is systemic, and the attack surface goes way beyond GPUs. The 59% vulnerable figure and 830-day patch delay numbers are the kind of data that should make OEMs uncomfortable. Not a novel exploitation technique, but genuinely useful ecosystem security research.