In this blog post we’ll discover and exploit a vulnerability which will allow us to gain code execution within Qualcomm’s Secure Execution Environment (QSEE) I’ve responsibly disclosed this vulnerability to Google and it has been fixed – for the exact timeline, see the “Timeline” section below. Qualcomm’s TrustZone implementation enables the “Normal World” operating system to load trusted applications (called trustlets) into a user-space environment within the “Secure World”, called QSEE. This is very dangerous; communication with TrustZone exposes a large (!) attack surface – if any trustlet that can be loaded on a particular device contains a vulnerability, we can exploit it.”]
Source: http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html

