Netlink, a socket family for IPC in Linux since 1999, is underexplored by security researchers in Android, leading to a buried attack surface. Divided into Classic and Generic categories, it poses security threats with vulnerabilities found in kernel modules, yielding 12 CVEs, emphasizing the importance of understanding Netlink mechanisms for secure Android system development and providing guidance on security measures. ```

Netlink is a hidden attack surface in Android kernel modules