# Fall of the machines: Exploiting the Qualcomm NPU (neural processing unit) kernel driver

DevFeed: [Fall of the machines: Exploiting the Qualcomm NPU (neural processing unit) kernel driver](<https://devfeed.tech/articles/fall-of-the-machines-exploiting-the-qualcomm-npu-neural-processing-unit-kernel-driver-68458.md>)

Original publisher: [Read original article](<https://github.blog/security/vulnerability-research/fall-of-the-machines-exploiting-the-qualcomm-npu-neural-processing-unit-kernel-driver/>)

Author: Man Yue Mo

Published: 2021-11-18T14:58:57Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [SELinux](<https://devfeed.tech/topics/selinux.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [aosp](<https://devfeed.tech/topics/aosp.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cpu](<https://devfeed.tech/topics/cpu.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [code](<https://devfeed.tech/tags/code.md>), [code-execution](<https://devfeed.tech/tags/code-execution.md>), [driver](<https://devfeed.tech/tags/driver.md>), [exploit-development](<https://devfeed.tech/tags/exploit-development.md>), [github-security-lab](<https://devfeed.tech/tags/github-security-lab.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [neural](<https://devfeed.tech/tags/neural.md>), [npu](<https://devfeed.tech/tags/npu.md>), [qualcomm](<https://devfeed.tech/tags/qualcomm.md>), [security](<https://devfeed.tech/tags/security.md>), [selinux](<https://devfeed.tech/tags/selinux.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

## AI overview

The article analyzes three vulnerabilities in Qualcomm's Android NPU kernel driver: a use-after-free and two information leaks. It explains how an untrusted app can combine them to execute arbitrary kernel code as root on affected Samsung devices, disable SELinux, and gain full device privileges. It also discusses the driver's exposure, the exploit mechanics, and delays in public fixes.

## Source excerpt

In this post, I'll use three bugs that I reported to Qualcomm in the NPU (neural processing unit) driver to gain arbitrary kernel code execution as root user and disable SELinux from the untrusted app sandbox in an Android phone.