
This deep dive breaks down CVE-2023-26083, where the Mali GPU driver serialized raw kernel pointers into a timeline stream ring buffer that unprivileged apps could acquire via ioctl and read using normal read operations. KASLR bypass primitive with user-space code: https://8ksec.io/cve-2023-26083-kernel-pointer-leakage-in-mali-gpus-timeline-stream-message-buffers Remained exploitable on Pixel 8 months after the announced patch. For researchers interested in topics like this, and our Offensive Android Internals course goes deeper into Android kernel internals, Mali GPU research, DAC/CAP/RKP/MTE, native fuzzing with Frida and AFL++, leads to the CASR certification. https://academy.8ksec.io/course/offensive-android-internals Follow @8kSec for more Android kernel research
Post summary
The post dissects CVE‑2023‑26083, detailing a kernel pointer leakage that enables a KASLR bypass via user‑space code, cites a PoC link, notes the bug was still exploitable after the patch, and invites researchers to study it further through their Android internals course.
