← Back to context

Comment by pbhjpbhj

9 hours ago

So Arm built in MTE but Google have decided to prevent access to it at the firmware level?

Have they introduced some other mitigations, for eg UAF, to improve memory safety?

It seems possible that nixing MTE is to prevent stomping on some TLAs exploits?

MTE requires several things to work well. Notably there is some missing hardware believed to be necessary for MTE to be performant on the pixel 11.

In terms of mitigation of UAF, a great deal of new code written for Android userspace these days is in memory safe languages such as rust. Also, a lot of testing with instrumented code sanitizers is still done before release. We don't know how much risk MTE actually mitigates.