About Me

Lukas Maar

Hey and welcome to my site. I am Lukas Maar, a Security Researcher at Calif and a Senior Security Researcher at ISEC, TU Graz. I completed my PhD thesis in 2025 under Stefan Mangard. My work focuses on low-level security: kernel exploitation, defenses, and side channels targeting the Linux and Android kernels, including KernelSnitch, a universal side channel for heap KASLR leaks. I have presented my research at USENIX Security, NDSS, Black Hat USA, Black Hat Asia, and Nullcon Berlin, among others.

Education
2025
Graz University of Technology
MSc in Electrical Engineering
2022
Graz University of Technology
BSc in Computer Science
2022
Graz University of Technology
BSc in Electrical Engineering
2018
Graz University of Technology

Notable Mentions

KernelSnitch
Universal heap KASLR leak
Hardware-agnostic timing side channel on kernel hash tables, yielding a universal heap KASLR leak, including MTE tag recovery. Confirmed on Linux and Android; macOS is also susceptible.
OEMpocalypse
Untrusted app to root
A generic page-UAF exploitation strategy against Android OEM kernel drivers, yielding full root chains on Samsung, Xiaomi, Oppo, OnePlus, and Realme devices.

2026
OEMpocalypse Now: A Generic Exploitation Strategy from Android Untrusted App to Root
Lukas Maar
CVE-2026-21102
Info
Privilege Escalation via a Page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver
Lukas Maar
CVE-2026-57551
Info GitHub Patch
From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks
Lukas Maar
Applied: Android 17 root (IonStack)
Info GitHub IonStack