Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day? Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable…
1: https://android-developers.googleblog.com/2019/05/queue-hard...
2: https://security.googleblog.com/2021/04/rust-in-android-plat...