Android Kernel Exploitation: Binder
Trainees master Binder internals and build a full local privilege escalation exploit for CVE-2023-20938, a use-after-free vulnerability, using Time Travel Debugging to trace kernel crashes, reverse-engineer heap states, and debug the exploit in a controlled Android 12 (aarch64) environment.
Module Overview

Master the internals of Android's Binder IPC mechanism, including its core data structures (binder_proc, binder_thread, binder_node), transaction flows, and lifetime management, building the foundation needed for kernel-level exploitation work.
Analyze a real use-after-free vulnerability in the Binder driver, from its root cause in misaligned offsets_size handling to the exploitation primitives it enables, including leaks and arbitrary read/write. Using Time Travel Debugging, you'll trace kernel crashes, reverse-engineer heap states, and debug complex race conditions and double-free scenarios.
Build a complete exploit chain for local privilege escalation: trigger the use-after-free via a two-process Binder setup, craft exploitation primitives such as leaks and arbitrary read/write, and overwrite credential structures to escalate privileges.
Use Time Travel Debugging to stabilize the exploit, identifying and resolving issues such as heap-spray evictions or double-free. The final exploit is validated in a controlled Android 12 (aarch64) emulator environment with vulnerable kernel images.
Over 10 Years of Hands-On Expertise.
Effective security testing comes from the combination of the right tools, deep technical knowledge, and the people who know how to apply them. eShard has spent over 10 years developing all three, and our coaching programs put that same expertise directly in your hands.
Frequently Asked Questions
Lorem ipsum dolor sit amet
Lorem ipsum dolor sit amet
Lorem ipsum dolor sit amet
Lorem ipsum dolor sit amet





