Nebula Security reveals Android 17 root exploit chain
Security researchers at Nebula Security have disclosed a proof‑of‑concept exploit named IonStack that can obtain full root access on Android 17. The chain links a vulnerability in Firefox for Android (affecting versions up to 151.0.2) with a long‑standing flaw in the Linux kernel’s rtmutex subsystem that existed since kernel 2.6.39 and was only fixed in kernel 7.1. By opening a specially crafted URL, an attacker can first execute code in the browser and then elevate privileges to the kernel, achieving complete device compromise.
Both components of the chain have already been patched: Mozilla released an update for Firefox for Android in early June, and the kernel fix is included in current Linux releases. Nebula Security reported no evidence of the exploit being used in the wild, emphasizing the need for users to keep browsers and operating systems up to date.