Android Virtualization Framework (AVF / pKVM) Architecture
Host Android OS Execution Level: EL1 State: Compromised Root Action: Snooping pVM RAM pKVM Hypervisor Execution Level: EL2 Mode: Host Deprivileged Stage-2 Page Table (S2PT) Host Mapping: UNMAPPED pVM Mapping: Read-Write Memory Ownership: pVM #1 STAGE-2 DATA ABORT Host EL1 Access Intercepted Protected Micro-Guest (pVM) Execution Level: Guest EL1 Protected Confidential Enclave Biometric Key: 0x1337_IRIS_DATA DRM / Keystore Applet Running
VULNERABLE Step: 0 / 4
Select an AVF / pKVM scenario above to observe hardware-enforced micro-guest isolation.
Security Insight: pKVM deprivileges the host Android kernel, preventing root compromises from leaking guest secrets.