<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>MT8696 on Raelize - Embedded Device Security Testing, Consultancy &amp; Training</title>
		<link>https://raelize.com/tags/mt8696/</link>
		<description>Recent content in MT8696 on Raelize - Embedded Device Security Testing, Consultancy &amp; Training</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Sun, 17 May 2026 23:00:00 +0200</lastBuildDate>
		
			<atom:link href="https://raelize.com/tags/mt8696/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>setresuid(⚡): Glitching Google&#39;s TV Streamer from adb to root</title>
				<link>https://raelize.com/blog/setresuid-glitching-google-tv-streamer-from-adb-to-root/</link>
				<pubDate>Sun, 17 May 2026 23:00:00 +0200</pubDate>
				<guid>https://raelize.com/blog/setresuid-glitching-google-tv-streamer-from-adb-to-root/</guid>
				<description>We attacked Google&amp;rsquo;s TV Streamer 4K with an ElectroMagnetic Fault Injection (EMFI) glitch on the Mediatek MT8696&amp;rsquo;s CPU. From an unprivileged adb shell, a single EM glitch during setresuid syscall makes the Linux kernel commit credentials with uid = 0. This is our hardwear.io NL 2025 talk in long form.</description>
			</item>
	</channel>
</rss>
