Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112) — Threadlinqs Intelligence
As of 2026-05-30, Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112) is a critical-severity vulnerability threat attributed to Saito Tech (Israel), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0177 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Attribution: Saito Tech · Israel · FINANCIAL
Google TAG identified Saito Tech (formerly Candiru) selling a 3-stage Android exploit chain to government customers. CVE-2026-22104 (CVSS 9.8) exploits a type confusion in the ART runtime for RCE via
Google's Threat Analysis Group (TAG) disclosed on March 5, 2026 a sophisticated 3-stage Android exploit chain developed and sold by Israeli commercial spyware vendor Saito Tech Ltd. (formerly Candiru Ltd., also known as Sourgum). The chain targets Android 12 through 15 across Qualcomm and MediaTek chipsets, with a bootloader-specific persistence mechanism affecting Google Pixel 7, 8, and 9 series devices.
**Stage 1 — ART Runtime Type Confusion RCE (CVE-2026-22104, CVSS 9.8)**
The initial compromise vector exploits a type confusion vulnerability in the Android Runtime (ART) dex2oat compiler. When a target installs or side-loads a specially crafted APK containing malformed DEX bytecode, the ART runtime incorrectly handles type resolution during ahead-of-time compilation. The type confusion allows an attacker to corrupt the vtable of a managed object, redirecting virtual method dispatch to attacker-controlled native code. This achieves remote code execution within the context of the target application process. The vulnerability is similar in class to CVE-2025-48543, a prior ART UAF that was also exploited in the wild. The crafted APK can be delivered via watering hole attacks, malicious ad injection (leveraging Candiru's known 'Sherlock' ad-based delivery mechanism), or direct social engineering links sent to targets.
**Stage 2 — Binder Driver Use-After-Free LPE (CVE-2026-22107, CVSS 8.4)**
Following initial code execution, the exploit chain escalates privileges from application context to kernel via a use-after-free in the Android binder IPC driver (drivers/android/binder.c). The vulnerability exists in the transaction buffer release path, where improper reference counting during binder_thread cleanup leads to a dangling pointer. The exploit uses cross-cache memory reallocation techniques — similar to those documented in CVE-2023-20938 and CVE-2022-20421 (BadSpin) — to reclaim the freed binder_transaction object with a controlled kernel object. This provides arbitrary kernel read/write primitives, which are used to disable SELinux, patch credential structures, and escalate to root. The exploit targets GKI kernel versions 5.10, 5.15, and 6.1 used across Android 12-15 devices.
**Stage 3 — Pixel Bootloader Secure Boot Bypass (CVE-2026-22112, CVSS 7.8)**
With kernel-level access, the final stage achieves persistence by exploiting a vulnerability in the Pixel bootloader's verified boot chain. A flaw in the Android Verified Boot (AVB) hash tree validation allows modification of the vendor partition without invalidating the dm-verity root hash. The exploit patches the bootloader's rollback protection index and injects a persistent implant into the vendor init sequence that survives factory resets and OTA updates. This stage specifically targets Google Pixel 7 (Tensor G2), Pixel 8 (Tensor G3), and Pixel 9 (Tensor G4) bootloaders. The persistence mechanism is reminiscent of the bootloader EoP CVE-2024-56184 disclosed in the March 2026 Pixel bulletin.
**Implant Capabilities**
Once deployed, the Saito Tech Android implant (an evolution of the DevilsTongue framework adapted for mobile) provides comprehensive surveillance: real-time GPS tracking, call interception, microphone and camera activation, message exfiltration from Signal/WhatsApp/Telegram, browser credential theft, IMEI/IMSI harvesting, contact and calendar exfiltration, and screen recording. The implant communicates over HTTPS with C2 infrastructure that impersonates legitimate mobile analytics and CDN services, consistent with Candiru's documented operational patterns.
**Attribution and Targeting**
Google TAG attributes the exploit chain to Saito Tech Ltd. with high confidence based on infrastructure overlaps with known Candiru C2 clusters, code-level similarities with the DevilsTongue Windows implant, and procurement documentation obtained during investigation. Active exploitation was confirmed against journalists in Lebanon and Turkey, political activists in Saudi Arabia a
Weaknesses (CWE)
CWE-843, CWE-416, CWE-345
Target sectors: government, media, civil-society, human-rights, telecommunications, legal
Target regions: Middle East, Southeast Asia, North Africa, Turkey, South Asia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-22104, CVE-2026-22107, CVE-2026-22112, T1190, T1566, T1189, T1203, T1204, T1547, T1542, T1068, T1027, T1553