Exploiting the Magic Leap One: Code Released

2025-05-18
Exploiting the Magic Leap One: Code Released

This repository publishes code for exploiting vulnerabilities in the Magic Leap One. The exploit leverages a stack overflow in Nvidia's SparseFS parser (sparsehax) and an oversized kernel device tree (dtbhax) to achieve code execution. These vulnerabilities may affect more than just the ML1; there's a possibility the kernel-dtb vulnerability could be used for persistence on autopilot units in certain cars using the TX2. The repo contains code for the Magic Leap console and a Rust-based Fastboot client for the host. Warning: Bricking your device is possible.

Hardware