Philipp Mao & Leo Larigauderie

Netflix and Pwn, Remotely Exploiting MediaTek Phones via the GenieZone Hypervisor

Abstract

MediaTek’s GenieZone is a type 1 hypervisor, deployed on all its mobile system-on-chips since around 2023. GenieZone’s main use case is the Mediatek TEE (M-TEE), a TEE which runs hypervisor applications (HAs) in isolated virtual machines.

GenieZone is used for secure video playback with HAs for h264, h265, and vp9 decoding of DRM-protected media. We discuss how attackers without access to a DRM license key can forge L1 widevine-protected MP4s, which causes the HAs to process attacker-controlled malformed bitstreams. We walk through how we discovered a heap buffer overflow in the h265 HA and how we exploited it to achieve code execution in the HA.

With code execution in the HA we present three bugs in the hypervisor triggerable by a HA, which either result in code execution in the hypervisor itself or the ability to map arbitrary physical memory. By combining one of these bugs with the h265 heap overflow we build a full chain exploit that pops a root shell on MediaTek Android phones with support for secure video decoding in GenieZone, just by the user opening an attacker-controlled website in Chrome.

Our presentation sheds light on a remote attack surface present in MediaTek SOCs and presents how attackers may use DRM-protected media to reach new decoding attack surfaces. We demonstrate the impact by exploiting vulnerabilities in these attack surfaces on various MediaTek-based phones.

BIO

Philipp is a PhD student in the Hexhive lab at EPFL, poking at the glue holding Android together. His prior work includes research on TEEs, system services and Scudo. In his free time he plays CTF, focussing on pwn challenges.

Léo is a Msc graduate from EPFL, who recently joined Synacktiv. Avid CTF player, he focuses on pwn. During his Msc thesis at EPFL, he did vulnerability research on Geniezone.