In the January 2017 Android Security Bulletin, Google provided a patch to CVE-2016-8462, an interesting vulnerabiltiy in the Pixels’ bootloader. I reported this issue to Google last December, but unfortunately got beat by Jon Sawyer (@jcase) and Sean Beaupre (@firewaterdevs), who reported it in October, so kudos to them!

My blog post about the vuln is available here

Jon Sawyer uploaded his PoC to his git as well: PixelDump.