Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
chronomaly-webos — CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG. | Kitploit
Tools/GitHubGitHub/analyticeth/chronomaly-webos
Embedded Systems SecurityPrivilege EscalationVulnerability AnalysisExploitationHardware SecurityLearning & EducationBinary Exploitation
GitHubanalyticeth/chronomaly-webos

chronomaly-webos

CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG.

View Repository
10134 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Chronomaly — CVE-2025-38352 on LG webOS

Kernel exploit for CVE-2025-38352 (POSIX CPU timer race condition / use-after-free) achieving persistent root on LG webOS Smart TVs running kernel 5.4.268 on ARM64. Verified on 4 TV models across multiple firmware versions. Responsibly disclosed to LG's Security Researcher Program (February 2026).

Built on Chronomaly by farazsth98. Stage 1 UAF race logic and cross-cache infrastructure ported and adapted for ARM64; Stages 2–5 redesigned with novel exploitation techniques and solutions to real-hardware constraints that do not exist in emulated environments. Developed with the assistance of Claude Opus 4.6.

See VULNERABILITY_REPORT.md for the full vulnerability analysis, exploit chain walkthrough, and recommended mitigations.

Results

  • Persistent kernel root (uid=0) from unprivileged prisoner user (uid=5038)
  • Verified on 5 LG TV models: OLED65C2PUA, 86QNED70AUA, OLED77C5PUA, OLED77G4WUA, OLED65C4PUA
  • Confirmed across firmware versions 33.22.65 – 33.30.97 (kernel 5.4.268-320 and -329)
  • Fully automated, completes within minutes, survives reboots via Homebrew Channel elevation
  • Reported to LG Security Researcher Program (February 7, 2026)

Disclaimer

This exploit was developed as part of responsible security research and reported to LG's Security Researcher Program on February 7, 2026. It is published for educational purposes only. Use responsibly and only on devices you own. The authors are not responsible for any damage, bricking, data loss, or warranty voiding resulting from use of this software. This software is provided as-is with no warranty.

Novel Techniques

1. Redesigned Write Primitive

The original's arbitrary decrement is slow and noisy: it sprays 1,000 struct cred objects via forked processes, then decrements a target cred's EUID field N times. Each decrement is a separate operation. This is acceptable in QEMU where timing is forgiving, but unreliable on real hardware where interrupt-driven page reclamation can steal pipe buffer pages between operations.

This was replaced with a single arbitrary write via list_del_init(). The exploit overwrites the UAF'd sigqueue's list_head.next and list_head.prev pointers through the pipe buffer. When the kernel dequeues the pending signal (collect_signal() → list_del_init()), it performs prev->next = next (writes the fake cred address into task_struct->cred) and next->prev = prev (controlled side-effect write). One write replaces the process's cred pointer with a pointer to a fake cred structure containing all-zero uid/gid fields. No cred spray, no forked processes, deterministic.

2. peek_pipe() via tee() for Non-Destructive Reads

The original uses destructive read() calls on pipe buffers throughout the exploit. In QEMU, this works fine because pages are not stolen between operations. On real hardware with 4 physical cores, the kernel's per-CPU page list (pcplist) aggressively reclaims freed pages. A destructive read releases the pipe buffer's backing page, which can be immediately stolen by a hardware interrupt before the exploit can reallocate it.

The solution is a non-destructive pipe read primitive using tee(). The tee() syscall duplicates pipe data between two pipes without consuming it, keeping the original pipe buffer's backing page pinned. This allows the exploit to read kernel data from the cross-cached pipe buffer repeatedly without risking page loss. This was critical for reliability on real hardware.

3. Fake Cred in Second Cross-Cached Pipe Buffer

The original sprays cred objects and hopes to land one in a predictable location. This version constructs the fake cred structure at a known address by performing a second cross-cache: allocate a new sigqueue (via tkill(SIGRTMIN+1)), learn its address from the first pipe buffer's heap leak, then cross-cache that sigqueue's slab page into a second pipe buffer. The fake cred is written into the second pipe buffer at the exact page offset of the leaked sigqueue address. The result is a fake cred at a deterministic kernel virtual address with no guesswork.

4. SIGUSR2 Kept Pending as Final Write Trigger

The original dequeues SIGUSR2 early in Stage 2 to leak the UAF sigqueue's address. This consumes the signal, so the original needs a different mechanism for the final write. This version never needs the UAF sigqueue's own address (the heap leak comes from adjacent sigqueue pointers in the pipe buffer). SIGUSR2 is kept pending across all five stages and its dequeue is used as the final arbitrary write trigger. The signal that created the UAF is the same signal whose dequeue exploits it.

5. modprobe_path + socket(44) Escalation

The fake cred structure has NULL user_ns, user, and group_info pointers (since the pipe buffer is zero-initialized beyond the uid/gid fields). Calling setresuid(), fork(), or exec() would dereference these NULL pointers and kernel panic. The original avoids this because its cred spray uses real cred objects with valid pointers.

The solution: overwrite /proc/sys/kernel/modprobe to point to a payload script (/tmp/pwn), then trigger call_usermodehelper via socket(44, SOCK_STREAM, 0) (requesting a non-existent protocol family). The kernel executes the modprobe helper with init_cred (the kernel's own root credentials, fully valid), bypassing the corrupted cred entirely. The payload runs as full root and can perform arbitrary operations.

6. Real-Hardware Timing Protection

The critical window in Stage 4 (writing malicious pointers into the pipe buffer, then triggering signal dequeue) is vulnerable to hardware interrupts stealing the pipe buffer page from the per-CPU page list. This does not happen in QEMU. On real hardware, this window is protected with SCHED_FIFO priority (when available) and sched_yield() to let pending work complete on the CPU before entering the critical section, plus pre-prepared buffer contents to minimize the time between write and trigger. The exploit also falls back gracefully when SCHED_FIFO is unavailable (as on webOS where the prisoner user lacks CAP_SYS_NICE).

7. ARM64 task_struct Offset Reverse Engineering

The arbitrary write targets task_struct->cred, which requires knowing the byte offset from task_struct->pending (whose address is leaked from the pipe buffer) to task_struct->cred. This offset is kernel-config-dependent. The 0x80 (128 byte) offset was manually computed from the LG webOS kernel source, accounting for CONFIG_KEYS=y, CONFIG_SYSVIPC=y, and ARM64-specific struct layout and alignment. The x86_64 offset in the original is different due to different struct packing and config options.


What It Does

On success, the exploit:

  1. Gains kernel root via UAF → cross-cache → arbitrary write (cred overwrite)
  2. Overwrites /proc/sys/kernel/modprobe to run a rooting payload as init
  3. The payload installs and elevates Homebrew Channel and removes Dev Mode app
  4. After reboot, Homebrew Channel provides persistent root SSH on port 22

Quick Start

Prerequisites

  • LG webOS TV with kernel 5.4.268 (ARM64)
  • Dev Mode enabled on the TV (SSH access on port 9922)
  • ARM64 cross-compiler (aarch64-linux-gnu-gcc)
  • Homebrew Channel IPK — download from webosbrew releases

Install Cross-Compiler

# macOS (requires third-party tap)
brew tap messense/macos-cross-toolchains
brew install aarch64-unknown-linux-gnu

# Ubuntu/Debian
sudo apt-get install gcc-aarch64-linux-gnu

Recommended: Install Homebrew Channel First

Download Tool