Get a Pentest and security assessment of your IT network.

News

QSEE privilege escalation vulnerability and exploit (CVE-2015-6639)

In this blog post we’ll discover and exploit a vulnerability which will allow us to gain code execution within Qualcomm’s Secure Execution Environment (QSEE) I’ve responsibly disclosed this vulnerability to Google and it has been fixed – for the exact timeline, see the “Timeline” section below. Qualcomm’s TrustZone implementation enables the “Normal World” operating system to load trusted applications (called trustlets) into a user-space environment within the “Secure World”, called QSEE. This is very dangerous; communication with TrustZone exposes a large (!) attack surface – if any trustlet that can be loaded on a particular device contains a vulnerability, we can exploit it.”]

Source: http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Tracking wearable devices could be very easy via Bluetooth Low Energy

News

Social Networks Part 1 Who exactly are you disclosing your life story to?