Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

PoC Released for Nothing Phone Code-Execution Vulnerability

A proof-of-concept exploit has been published for a critical flaw in the secure boot process of the Nothing Phone (2a) and CMF Phone 1. This exploit can break the chain of trust and allow full code execution at the highest privilege level, posing a…

A proof-of-concept exploit has been published for a critical flaw in the secure boot process of the Nothing Phone (2a) and CMF Phone 1. This exploit can break the chain of trust and allow full code execution at the highest privilege level, posing a severe risk to device security.

A logic flaw in the MediaTek secure boot chain affects the Nothing Phone (2a) and likely other MediaTek devices. When the device’s bootloader is unlocked, the Preloader skips the verification of the bl2_ext partition. This partition is supposed to verify all subsequent boot stages, but with the flaw, it is never checked. By exploiting this gap, an attacker can run arbitrary code at EL3, the highest privilege level in the system, and disable the secure boot chain after Preloader execution.

The published proof-of-concept, named fenrir , patches the function sec_get_vfy_policy() in bl2_ext to always return zero. This bypasses the authentication policy and allows any boot image to load without checks. The exploit also spoofs the device’s lock state to appear locked, permitting integrity checks to pass while still unlocked.

The PoC includes Python, C, and shell scripts to automate the patching and flashing process.

Build Process:

A proof-of-concept exploit has been published for a critical flaw in the secure boot process of the Nothing Phone (2a) and CMF Phone 1.
Mark Jensen · Thehackingpost

Place the original bootloader image in bin/[device].bin Run ./build.sh pacman (or supply a custom path) This produces a patched file named lk.patched

Flashing:

Use ./flash.sh to upload the patched image to the device via fastboot If fastboot is unavailable, alternative flashing methods may be required

The PoC also registers custom fastboot commands and can dynamically call built-in bootloader functions. However, memory modification at runtime currently triggers MMU faults and remains a work in progress.

Advertisement

This vulnerability undermines the entire chain of trust on affected devices. Once exploited, attackers can install unauthorized operating systems or manipulate firmware without detection. The flaw has been confirmed on the Nothing Phone (2a) and CMF Phone 1, and preliminary testing suggests other MediaTek-based phones like the Vivo X80 Pro may also be at risk.

Users should avoid unlocking their bootloaders until an official patch is released. Device makers and chipset vendors must update the secure boot verification to enforce checks on bl2_ext even when unlocked. Security teams should monitor for unauthorized flashing activity and advise end users to re-lock their bootloaders once official updates are applied.

The full PoC repository, including detailed explanations, scripts, and usage instructions, is available under the AGPL-3.0 license on GitHub. Security researchers and device vendors are urged to review the code and integrate proper verification measures to restore a secure boot chain.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories