Does anyone check Mediatek's security bulletins for vulnerablities? - Fire HD 8 and HD 10 Android Development

After lurking here waiting for updates on things, I know there's currently a big snag on gaining root on the latest firmware due to Amazon's locked down bootloader. I've been readng around, and it does seem like there are privelige escalation exploits out there for the Mediatek chip inside the latest Fire:
https://corp.mediatek.com/product-security-bulletin/January-2022 (do a find for MT8183)
Not sure how helpful that is, I'd be very surprised if that information wasn't already in the hands it needs to be, but I thought I'd try and be as helpful as possible by pointing it out.

@Datastream33 @diplomatic

badboy21102000 said:
@Datastream33 @diplomatic
Click to expand...
Click to collapse
Looks like there's a total of 5 exploits, and they're driver related. Hmm...

Related

Today's update.

Just got a small update. Anyone know what's in it? 6.0 prep maybe?
jwl12345 said:
Just got a small update. Anyone know what's in it? 6.0 prep maybe?
Click to expand...
Click to collapse
It´s just a security patch rolling out right now !
jwl12345 said:
Just got a small update. Anyone know what's in it? 6.0 prep maybe?
Click to expand...
Click to collapse
A big update needs a small prep update???? Never heard LOL
Too many video games, I guess. Was half asleep and forgot that that's just not how this works lol
Lousy timing on AT&T. I have been trolling waiting for this update and got really excited. Would have been OK with even an update to unlock the FM radio but alas, we just have a generic update.
exxTErno said:
It´s just a security patch rolling out right now !
Click to expand...
Click to collapse
Thanks, I had no clue one was on the way so I came to see what it was.
I was hoping, had my fingers crossed. Went way too quickly. ?
Sent from my SAMSUNG-SM-N910A using XDA-Developers mobile app
note 4 SM-N910A at&t update?
does anyone know when the 6.0 update will be released? my phone is unlocked will this affect the OTA update?
mejiachach said:
does anyone know when the 6.0 update will be released? my phone is unlocked will this affect the OTA update?
Click to expand...
Click to collapse
So you intentionally rooted/ hacked the software and now are worried about getting it?
lol
dave30534 said:
So you intentionally rooted/ hacked the software and now are worried about getting it?
Click to expand...
Click to collapse
No i didn't "root/hack the software" lol . i haven't even received the phone from retailer. this phone is factory unlocked. IMO or experiences this will not affect it but wanted a third opinion.
dave30534 said:
So you intentionally rooted/ hacked the software and now are worried about getting it?
Click to expand...
Click to collapse
Unlocked doesn't mean that it was hacked or rooted. It means that you can use any carrier's sim card in it.
Sent from my SAMSUNG-SM-N910A using Tapatalk
mejiachach said:
No i didn't "root/hack the software" lol . i haven't even received the phone from retailer. this phone is factory unlocked. IMO or experiences this will not affect it but wanted a third opinion.
Click to expand...
Click to collapse
I'm no expert, but the way I think it works is that if your phone's not AT&T branded you won't get the update as they are AT&T version specific. If you want to check for and get any kind of updates you'll probably have to go through Samsung's Kies program.
Sorry, misread on the unlocked part.
I just got lots of updates from the play store, one of which is the new Samsung Browser that is included in 6.0 Marshmallow
ok thanks Kyuta Syuko for the information
dave30534 said:
Sorry, misread on the unlocked part.
I just got lots of updates from the play store, one of which is the new Samsung Browser that is included in 6.0 Marshmallow
Click to expand...
Click to collapse
The Samsung Browser update wasn't tied to this update, Samsung updated the browser to work with Lollipop.
Download This Small Update
Any one know where i can download this update and update manually? I have a att note 4 on tmobile. I use to be a att customer. But i was told by tmobile that my device software updates have to come from att because i have a att branded version of the note 4.
yasirfaheem said:
Any one know where i can download this update and update manually? I have a att note 4 on tmobile. I use to be a att customer. But i was told by tmobile that my device software updates have to come from att because i have a att branded version of the note 4.
Click to expand...
Click to collapse
You don't really need this, just a small security update, wait for M it'll be included
www.engadget.com/2016/04/04/android-april-security-update
floatingtrees said:
You don't really need this, just a small security update, wait for M it'll be included
Click to expand...
Click to collapse
If i had att i would be able to install this update on my phone and would not even need to ask about this. But i no longer have att and have tmobile and want to have all the latest bug and os patches even though you think i do not need it.
www.engadget.com/2016/04/04/android-april-security-update
Android's April security update tackles another Stagefright flaw
You'll want to update in short order.
Google's monthly Android security updates are nothing new, but its latest release may be particularly important. The new April update tackles eight critical vulnerabilites that include one in the libstagefright library -- you know, the same media framework that recently faced a rash of real and potential exploits. It also patches a nasty kernel flaw that would give attackers full control over your device. You'll get first crack at the fixes if you either have a Nexus device or can install an Android Open Source Project build, but other vendors that offer Google's monthly updates will likely follow suit before long.
Now tell me that i do not need this update!
yasirfaheem said:
If i had att i would be able to install this update on my phone and would not even need to ask about this. But i no longer have att and have tmobile and want to have all the latest bug and os patches even though you think i do not need it.
www.engadget.com/2016/04/04/android-april-security-update
Android's April security update tackles another Stagefright flaw
You'll want to update in short order.
Google's monthly Android security updates are nothing new, but its latest release may be particularly important. The new April update tackles eight critical vulnerabilites that include one in the libstagefright library -- you know, the same media framework that recently faced a rash of real and potential exploits. It also patches a nasty kernel flaw that would give attackers full control over your device. You'll get first crack at the fixes if you either have a Nexus device or can install an Android Open Source Project build, but other vendors that offer Google's monthly updates will likely follow suit before long.
Now tell me that i do not need this update!
Click to expand...
Click to collapse
Relax no one's gonna target you and "hack into your phone" if your worried about stagefirght then you shouldn't rely on att or Samsung for that matter to patch it, consider using a texting app that offers protection instead like textra. Anyway good luck finding that 60mb insignificant update file that no one will bother to upload
Stagefright was patched way before this and even though we just got the update, we still don't have the latest patch

Regarding Root and Android 7

So I read an Article
That states
Using a feature called verified boot, Android 7.0 Nougat will check the cryptographic integrity to detect if your device has been tampered with.
Click to expand...
Click to collapse
With that said, will there ever be root again for android 7 and up?
so, with cm14 at least, i believe root is included. If anything i think it will just disable certain features if the device has been rooted. although i suppose that it would depend on the manufacturer. It will certainly be more difficult with samsung, anyways. I'm done with samsung after this one, though. samsung has been bending root users over the table since knox was first included with consumer phones - since before then, but it was a minor inconvenience before then.
when they didn't include adoptable storage with their marshmallow update, i was OUT! looking at the lg v20 now, i sampled it for a bit and it literally made me want to throw my note 4 in the trash
Look at the Pixel, Android 7.1 + root, It's possible. We're not getting official Android 7.x more likely than not, but it's possible to root 7.x.
I'm running CM14.1 on this device and SuperSU is just fine.
RDChase said:
Look at the Pixel, Android 7.1 + root, It's possible. We're not getting official Android 7.x more likely than not, but it's possible to root 7.x.
Click to expand...
Click to collapse
Thank you this is the answer I was looking for.

LineageOS developers wanted

Seeing as this phone finally has bootloader unlock available, how do we go about getting some capable devs to begin supporting LineageOS for this phone?
Was the launch botched enough that there just isn't any dev interest?
I'm thinking so, It's been out a while now, no bootloader unlock and we're still (570KL) waiting for nougat.
I believe a lot of devs are waiting for the bigger better releases due out in a month or 3....
ASUS may very well have killed off dev interest before this great piece of hardware was fully recognised by our community....
Duplicated thread
jsheradin said:
Seeing as this phone finally has bootloader unlock available, how do we go about getting some capable devs to begin supporting LineageOS for this phone?
Was the launch botched enough that there just isn't any dev interest?
Click to expand...
Click to collapse
shakalaca may release in this week, but it was still in alpha phase.It might have many problems.news of lineage 14.1 for zenfone 3

Root, Fastboot, Bootloader Unlock, TWRP and Magisk - All in One Guide for NOOBS

Guides will be published shortly
Credits to
@j4nn
@Inerent
@漠云
@Markus
@vlad48
Permanent Root, Magisk, Twrp and Bootloader Unlock was achieved for all V50 koreans
Other LG Snapdragon 855 should follow in the next days/week. Stay tuned for guides and news.
until then follow our telegram channel for more chat like discussions...
Any news on this, here in Oz we've been abandoned by LG to having only Android 9...
Everytime we ask about it LG says it's up to Google to release the update... What a crock since the rest of the world has it, we are the ONLY country yet to get Android 10...
This might give a little love to our forgotten, EXPENSIVE FLAGSHIP...
Last time I'm buying LG I'll tell you that...
ultramag69 said:
Any news on this, here in Oz we've been abandoned by LG to having only Android 9...
Everytime we ask about it LG says it's up to Google to release the update... What a crock since the rest of the world has it, we are the ONLY country yet to get Android 10...
This might give a little love to our forgotten, EXPENSIVE FLAGSHIP...
Last time I'm buying LG I'll tell you that...
Click to expand...
Click to collapse
He's already shown that it's possible, give them time to develop the steps/guide to do it. Don't ask for ETAs, basic XDA rule.
Hi guys! Please be patient as there were some bricked devices.
All korean V50 can have this and also some G8.
If you dont have patience, join telegram group V50 and ask for help from Vlad48 aka VL48. White user also has the knowledge and also contributed a lot to this, but he doesnt speak english that good and you may get confused in doing things that will brick your phone.
I'm waiting to make an ALL IN ONE guide with everything in that ADB folder so that we will donwload just one file.
Almost all bricked devices so far were because of WRONG file placement inside adb folder if you believe it ...
That's no worries, not wanting an ETA.
Sorry, went off on a tangent there earlier due to overwork and night shift.
As I said, here in Oz we've been stranded with Android 9, security update is for Oct 19, with no Android 10 release in sight and only excuses and buck passing from LG.
Do we know if this will allow Android 9 to be rooted and, finally, be updated to the latest OS?
Cheers guys...
ultramag69 said:
That's no worries, not wanting an ETA.
Sorry, went off on a tangent there earlier due to overwork and night shift.
As I said, here in Oz we've been stranded with Android 9, security update is for Oct 19, with no Android 10 release in sight and only excuses and buck passing from LG.
Do we know if this will allow Android 9 to be rooted and, finally, be updated to the latest OS?
Cheers guys...
Click to expand...
Click to collapse
Yeah, there may be an issue there... You can only use temp root on Android 10. Specifically what phone model (carrier/region that the phone is from) do you have? I don't mean your current carrier necessarily, just the branding of your model.
antintin said:
Yeah, there may be an issue there... You can only use temp root on Android 10. Specifically what phone model (carrier/region that the phone is from) do you have? I don't mean your current carrier necessarily, just the branding of your model.
Click to expand...
Click to collapse
It's the LM-V500EM, like Europe, however, it is distributed exclusively through Australia by Telstra.
This means we can't upgrade using another country's firmware but also, as we aren't part of Europe and UK, we can't unlock the bootloader. :crying:
Again, every time LG is asked about newer firmware the finger is pointed at Google.
When Telstra is asked, mostly just the sound of silence but if you do hear whispers it's no firmware has as yet been supplied and to check with the manufacturer of the device.
Google also has the advice Telstra give about the updated firmware which puts LG in the drivers seat and they're still sitting at the bar at the start of happy hour as far as Australia is concerned, and every hour is happy hour..
Hence we need to be able to unlock the bootloader and root to update our expensive and, supposedly flagship device.
You understand the frustration and impatience...
should we be looking for a brand in particular of the phone beside the korean one? Plannign to upgrade my v30
kventura said:
should we be looking for a brand in particular of the phone beside the korean one? Plannign to upgrade my v30
Click to expand...
Click to collapse
Hi, i recommend v50 koreans due to battery life and 5g.
G8 Sprint is now bl unlockable at lower price and nice compact form factor
Just got my v50 u+ recently
Cant wait for the script
Can't wait for these guides, thank you to all involved!
If I may make a request, perhaps a guide on how to hide root, using Magisk, so that banking apps can still be used?
Thanks again
shadders said:
Can't wait for these guides, thank you to all involved!
If I may make a request, perhaps a guide on how to hide root, using Magisk, so that banking apps can still be used?
Thanks again
Click to expand...
Click to collapse
That's a pretty generic guide; just use magisk hide and the props config module, but lots of modules may break safety net
antintin said:
That's a pretty generic guide; just use magisk hide and the props config module, but lots of modules may break safety net
Click to expand...
Click to collapse
I see thanks. If a module breaks safety net, does uninstalling that module mean the device passes safety net again? Or is the device just permanently marked as unsafe?
shadders said:
I see thanks. If a module breaks safety net, does uninstalling that module mean the device passes safety net again? Or is the device just permanently marked as unsafe?
Click to expand...
Click to collapse
You might have to wipe data for all the Google apps (or possibly even factory reset), but it shouldn't be permanent
antintin said:
You might have to wipe data for all the Google apps (or possibly even factory reset), but it shouldn't be permanent
Click to expand...
Click to collapse
I see thank you
Inerent said:
Guides will be published shortly
Credits to
@j4nn
@Inerent
@漠云
@Markus
@vlad48
Click to expand...
Click to collapse
Not to sound like a jerk, but I do think it's a valid question... what is the point of creating a thread promising a comprehensive 'All in one guide' to be 'released shortly', and also posting in the other root thread that a guide will be available, and then nearly a month later, there is still no guide? Again, I don't want to sound like a jerk because you're trying to help, but so far, you have just made empty promises and gotten peoples hopes up but not actually provided anything
(again, not trying to sound harsh, just posting as someone who has been keeping an eye on this for a month and now feeling frustrated)
Sorry, dont have time for this, anyone can make a new thread or admin delete this...
Until then, all is available on telegram.
Inerent said:
Sorry, dont have time for this, anyone can make a new thread or admin delete this...
Until then, all is available on telegram.
Click to expand...
Click to collapse
very disappointing after waiting so long...
antintin said:
Yeah, there may be an issue there... You can only use temp root on Android 10. Specifically what phone model (carrier/region that the phone is from) do you have? I don't mean your current carrier necessarily, just the branding of your model.
Click to expand...
Click to collapse
Samsung A715F telcel mexico (Android 10)
Can we root it , unlock it. Etc? Thanks in advance
Sent from my [device_name] using XDA-Developers Legacy app

Question Building AOSP for Red Magic 8 Pro

I'm looking to build AOSP for the Red Magic 8 Pro. Has anyone managed to get the proprietary binaries from Nubia or extract it from the stock firmware?
I have tried searching around for these binaries to no avail. If someone has a download link to share I would really appreciate it. I just want a completely stock android experience and don't mind if not everything isn't working.
Do you really want AOSP or Paranoid Android will do as well? In any case, download OTA here, extract payload.bin and use payload-dumper-go. You can use LineageOS instructions for getting binaries from unpacked .omg files.
aaa.bbb111222 said:
Do you really want AOSP or Paranoid Android will do as well? In any case, download OTA here, extract payload.bin and use payload-dumper-go. You can use LineageOS instructions for getting binaries from unpacked .omg files.
Click to expand...
Click to collapse
Have they already released a ROM for this phone? If not, AOSP builds without most Google trash and I block many of their domains in the hosts file just in case. I did finally find a dump here: https://github.com/RandomPush/nubia_nx729j_dump
Appreciate your help though. I'll post my progress here in case anyone is interested. The android developer documentation says proprietary binaries are usually located in a /vendor partition. Going through the dump now and trying to figure out the bare minimum to get a custom ROM booted.
My guesses are anything Qualcomm related for the SoC. I'm unsure of what baseband/radio chips the phone uses, actually it's been pretty tough to find a good spec sheet on it. Most resources that come up on Google only refer to surface level specs and don't go into much detail on the chips themselves.
No, they haven't, but I've seen people working on it. It would be a bit easier to bring up because PA is CLO-based (not AOSP), so the probability of most stuff working is higher. CLO has some Qualcomm-specific patches. Actually, you can probably build QSSI (like GSI but from CLO) without much difficulties, so this might be the way to go.
I'd recommend that you extract those binaries from OTA anyway as they might be updated in the future. Out of the box you probably won't get working vibration.
With the kernel source released, what's so difficult with building LineageOS and stuff?
SevastianXDA said:
With the kernel source released, what's so difficult with building LineageOS and stuff?
Click to expand...
Click to collapse
We need a good unbricking method just to be on the safe side (personally, I'm not very keen on even trying someone else's build, let alone making my own, simply too much risk). Other than that, a lot of time is needed and there are basically zero good instructions. Once again, LOS isn't the best option for 8g2, would be better to go for Paranoid Android. One can theoretically build QSSI image (basically GSI, but for Snapdragons), might be a good idea for now. Still risky tho
aaa.bbb111222 said:
We need a good unbricking method just to be on the safe side (personally, I'm not very keen on even trying someone else's build, let alone making my own, simply too much risk). Other than that, a lot of time is needed and there are basically zero good instructions. Once again, LOS isn't the best option for 8g2, would be better to go for Paranoid Android. One can theoretically build QSSI image (basically GSI, but for Snapdragons), might be a good idea for now. Still risky tho
Click to expand...
Click to collapse
What are the bricking issues here? Usually even if the ROM is f*cked or just something doesn't work you can always flash back to stock through TWRP.
SevastianXDA said:
What are the bricking issues here? Usually even if the ROM is f*cked or just something doesn't work you can always flash back to stock through TWRP.
Click to expand...
Click to collapse
If only there was a fully working TWRP... Unfortunately, there isn't. Well, kind of. It boots but that's it. And no, sideload simply doesn't work. When I went back to stock on my previous device (1+7 Pro), I had to use MSM Tool. Nothing like that is available for RM8P, ZTE doesn't want to give the tools to us because of bs reasons.
aaa.bbb111222 said:
If only there was a fully working TWRP... Unfortunately, there isn't. Well, kind of. It boots but that's it. And no, sideload simply doesn't work. When I went back to stock on my previous device (1+7 Pro), I had to use MSM Tool. Nothing like that is available for RM8P, ZTE doesn't want to give the tools to us because of bs reasons.
Click to expand...
Click to collapse
Bruuuuhhh, that's stupidd, someone shall reverse engineer the MSM tool to work for the RM8P (sarcasm)
Hmm, as I can see from this post, it seems peeps have managed to actually restore the phone from a full brick..: Post
Edl or its countparts is not a necessity for buiding a custom rom. 1st, a custom rom usually just overwrite the application parts, so in the worst case the user can still restore to factory rom via fastboot commands. 2nd, many manufacturers never release their factory rescue tools (Google, ?) but there are numerous custom roms, even official builds.
Cyanide_zh said:
Edl or its countparts is not a necessity for buiding a custom rom.
Click to expand...
Click to collapse
True, it's more a convenience factor.
Cyanide_zh said:
1st, a custom rom usually just overwrite the application parts, so in the worst case the user can still restore to factory rom via fastboot commands.
Click to expand...
Click to collapse
Or not. In fact, happened to me (Qualcomm crashdump mode or something like that). And if something could go wrong, it will.
Cyanide_zh said:
2nd, many manufacturers never release their factory rescue tools (Google, ?) but there are numerous custom roms, even official builds.
Click to expand...
Click to collapse
Usually those devices have much less ROMs available if any. Just compare 1+9 Pro and 10 Pro.
aaa.bbb111222 said:
less ROMs available if any. Just compare 1+9 Pro
Click to expand...
Click to collapse
Any ROM than the stock would do, just LineageOS would be superb.
SevastianXDA said:
Hmm, as I can see from this post, it seems peeps have managed to actually restore the phone from a full brick..: Post
Click to expand...
Click to collapse
Interesting.. https://romprovider.com/nubia-red-magic-8-pro-plus-firmware-stock-rom/
SevastianXDA said:
Interesting.. https://romprovider.com/nubia-red-magic-8-pro-plus-firmware-stock-rom/
Click to expand...
Click to collapse
sadly, 9008 firmware need pay about 50 USD, But nobody said the package can be used still now.
CrazyMoney said:
sadly, 9008 firmware need pay about 50 USD, But nobody said the package can be used still now.
Click to expand...
Click to collapse
Bruh the custom ROM and modding community is so mid and goofy for the RM8P Literally one of the main things making me go for a Poco F5 instead
Chinese dev made MIUI rom but its only payed with alipay for like 3 dollars. I im waiting when we can pay with paypal to try it looks good.
ibestmoder said:
Chinese dev made MIUI rom but its only payed with alipay for like 3 dollars. I im waiting when we can pay with paypal to try it looks good.
Click to expand...
Click to collapse
Well yeah, but as explained/talked about here, AOSP/LineageOS has to be technically possible
I got the rom maybe extract and check it? Take out alipay security then we can try it
ibestmoder said:
I got the rom maybe extract and check it? Take out alipay security then we can try it
Click to expand...
Click to collapse
Maybe share the ROM file, then we can try finding some way to remove forced payment/crack it (No paid ROMs allowed in XDA forums) and maybe possibly clean it somewhat (Does it even have english as an option?) and we'll finally get ourselves a finally working alternative custom ROM.

Categories

Resources