The postmarketOS and Alpine Linux Conference

Dieses (U-)Boot ist unsinkbar: UEFI-capable firmware on MediaTek devices
2026-09-25 , 5053.1 (Großer B-IT Raum)

MediaTek devices have a vulnerability which allows us to replace LK2 (Little Kernel 2, first-stage payload) with our own. We exploit it to clean-up the boot chain and gain full control over our devices.


Placeholder for now, we also want to cover barebox work ninelore and tree did on Chromebooks.

Showcases:

  • Zinwa Q25 (zinwa-q25) running U-Boot and mainline Linux booted with UEFI (MT8781)
  • Motorola Moto G72 (motorola-vicky), same thing (MT6789)
  • Acer Chromebook Spin 513 (google-tomato) (barebox, MT8195)
  • Lenovo IdeaPad Slim 3 Chromebook (U-Boot(?), MT8186)

Hack the planet!

This speaker also appears in:

thread 'main' (2137) panicked at 9lore.rs:2:1:
Caffeine and Methylphenidate not found
note: run with RUST_BACKTRACE=1 environment variable to display a backtrace