[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-android-blocks-risky-gpu-ioctls-with-new-selinux-policy":10,"sections":49},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":38,"persona_id":22,"persona_name":22,"section":39,"tags":40,"sources":44,"feedback":48,"feedback_at":22,"cost_usd":48,"total_tokens":48},1039,"android-blocks-risky-gpu-ioctls-with-new-selinux-policy","Android 16 Locks Down GPU Driver Access to Shrink Attack Surface","Google is walling off GPU debugging commands from regular apps in Android 16, targeting the driver interface behind most Android kernel exploits since 2021.","Google is tightening Android's GPU driver — not by patching individual bugs, but by making entire categories of commands unreachable from regular apps.\n\nThe Android Security team, working with chip designer Arm, deployed a new SELinux policy landing in Android 16 that sorts Mali GPU driver commands into three buckets: production, instrumentation, and debug. Regular apps now get access to only the production set; the profiling and debugging commands developers use — and that attackers have been exploiting — are blocked by default. Developers who need instrumentation access can still opt in on rooted devices or by flagging their app as debuggable in its manifest. Google staged the rollout cautiously, auditing what broke under the new restrictions before enforcing them broadly.\n\nGPU exploits have been the dominant attack vector for Android kernel drivers since 2021 — the post states this plainly, without corporate softening. The Mali driver sits at the seam between user space and the kernel, so a flaw there can mean full device compromise. Restricting attack surface does not fix existing bugs, but it narrows the list of entry points an attacker can reach before finding one.\n\nThe fact that debugging interfaces were accessible from production apps at all is the kind of oversight that tends to look obvious in hindsight — and expensive when it turns up in an exploit chain targeting a chip found in billions of devices.","[\"android\",\"gpu\",\"security\",\"selinux\"]","2025-12-09T17:00:00.008Z","2026-06-16T05:49:59.474Z","2026-06-18T14:00:22.594Z","published",null,[24,30,34],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Add a concise concluding paragraph that restates the impact of the new SELinux GPU hardening and what readers should watch for next.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"Add a concise concluding paragraph that restates the impact of the new SELinux GPU hardening and suggests what readers should watch for next.",{"id":35,"reviewer":26,"round":36,"reason":37,"status":29},"editor-r3",3,"Remove the placeholder token in the sentence about GPU exploits, add a clear concluding paragraph that restates the impact of the SELinux GPU hardening and notes what to watch for next.","https:\u002F\u002Fcdn.xyz.onl\u002Farticle-images\u002Fandroid-blocks-risky-gpu-ioctls-with-new-selinux-policy.webp","security",[41,42,39,43],"android","gpu","selinux",[45],{"name":46,"url":47},"Google Security Blog","http:\u002F\u002Fsecurity.googleblog.com\u002F2025\u002F12\u002Ffurther-hardening-android-gpus.html",0,{"sections":50},[51,56,60,65,70,75,80,85,90,95,100,105,110,115],{"name":52,"slug":53,"count":54,"latest_published_at":55},"AI","ai",2602,"2026-07-18T18:30:00.000Z",{"name":57,"slug":39,"count":58,"latest_published_at":59},"Security",315,"2026-07-17T19:30:00.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Policy","policy",169,"2026-07-17T19:49:53.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Hardware","hardware",126,"2026-07-16T20:09:48.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Consumer Tech","consumer-tech",94,"2026-07-16T16:29:46.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Software","software",72,"2026-07-17T09:42:05.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Science","science",66,"2026-07-10T10:29:37.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"Dev Tools","dev-tools",60,"2026-07-16T16:59:13.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Startups","startups",42,"2026-07-16T16:30:35.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":106,"slug":107,"count":108,"latest_published_at":109},"General","general",29,"2026-07-10T22:28:58.000Z",{"name":111,"slug":112,"count":113,"latest_published_at":114},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":116,"slug":117,"count":118,"latest_published_at":119},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]