A proof-of-concept (PoC) exploit has been released for a critical vulnerability in the secure boot chain of Nothing Phone (2a) and CMF Phone 1, potentially affecting other devices using MediaTek.
See also: Nothing: The new Phone 3A and 3A Pro with AI

The exploit, codenamed Fenrir and published by researcher R0rt1z2, allows arbitrary code to be executed at the highest privilege level, effectively defeating the secure boot process.
The vulnerability stems from a logic error in the MediaTek boot chain, where a key component is not properly verified when the bootloader is in an unlocked state. It is located in the Preloader of the MediaTek boot process. When a device's bootloader is unlocked (seccfg is set to unlocked), the Preloader fails to verify the cryptographic signature of the bl2_ext. This omission is critical because bl2_ext is responsible for verifying all subsequent components in the boot chain.
The Preloader transfers execution to bl2_ext while still operating at Exception Level 3 (EL3), the highest privilege level in the ARM architecture. An attacker can therefore modify bl2_ext to bypass all subsequent signature checks, causing a complete breakdown of the chain of trust and allowing unverified and malicious code to be loaded.
See also: The future of Nothing: Smartphones with artificial intelligence

By exploiting this flaw, an attacker can achieve code execution in EL3, giving them deep control of the device before it even starts loading the main operating system. The PoC demonstrates this by modifying a single function, sec_get_vfy_policy(), to always return a value of 0, tricking the bootloader into thinking that all subsequent images are verified. The released exploit includes a payload that can register custom fastboot, control the device's boot mode, and dynamically call native bootloader functions.
Additionally, the PoC can spoof the device's locked state, making it appear as "locked" to pass strong integrity checks even when the bootloader is unlocked. The researcher notes that while the current payload cannot modify memory during execution due to MMU errors, the exploit provides a strong foundation for further development.
The exploit has been confirmed to work on the Nothing Phone (2a) (codenamed “Pacman”) and the CMF Phone 1 (codenamed “Tetris”). The exploit creator also notes that the Vivo X80 Pro is affected by a similar, and possibly more serious, vulnerability where bl2_ext is not verified even with a locked bootloader. The issue is believed to also exist on other MediaTek devices that use “lk2” as a secondary bootloader.
See also: Nothing Phone's first Special Edition smartphone 2a

The researcher has issued a strong warning, stating that any attempt to use the exploit can cause permanent damage or “brick” a device if not executed correctly. Users are advised to be extremely careful, as the process involves flashing a modified bootloader image that can lead to irreversible hardware damage.
