We discovered a privileged process arbitrary code execution vulnerability in Android 17. This vulnerability was patched in Android 17 QPR1 but was not included in any security bulletin. Combined with the dirty frag vulnerability (CVE-2026-43284), we achieved full root privilege escalation on Android 17.0.
The DirtyFrag vulnerability was disclosed 3 months ago but is still exploitabe, because Google has delayed the release frequency of vulnerability patches, changing from monthly to quarterly security bulletins. In the AI era, this behavior is completely incomprehensible. A large number of devices in the Android ecosystem are vulnerable to attacks due to the vulnerability details leaked in the Pixel system; even Pixel devices not participating in the beta program are not immune.
Therefore, we used two "already patched" vulnerabilities to demonstrate full rooting on Google Pixel 10 with the latest patches as a warning, urging Google to change its practices and release vulnerability patches promptly.