a way to get root (in a limited SELinux context) without bootloader unlock on all Pico headsets (only tested on a Pico 4 Enterprise)
drop hashsu.sh into /sdcard like so with adb:
adb push hashsu.sh /sdcard/hashsu.shyou can now just run
adb shell /system/bin/sh /sdcard/hashsu.sh -c 'id'and get back
uid=0(root) gid=0(root) groups=0(root),1003(graphics),1006(camera) context=u:r:pvrtrackingservice:s0
you now have root!
all pico headsets ship with a system service called pvrtracking, it registers a android Binder interface, with one code to get a md5 checksum of a file.
it does this by doing popen("md5sum <usercstring>", "r"). popen is notably a /bin/sh -c wrapper, meaning we can do a command injection to gain code execution in the context and do whatever we want.
SELinux will prevent us calling this Binder normally but adb service call luckily can, but the types it accepts don't have a byte vector, so we have to get creative by encoding a byte vector into a set of i32s, you can see this achieved in generate_service_call.py (which you do not have to touch)
so our payload is as simple as a Parcel with a byte vector of $(/system/bin/sh /sdcard/hashroot-run.sh) that we send to the service, and it will run it as root
various other system services may be vulnerable to similar things which could allow us to escalate our SELinux context even further and even maybe get KernelSU running, somehow, some way. i tried looking into it and there's a lot of promising gadgets but nothing conclusive.
if you want true root, go to pico4.wiki