Get a Pentest and security assessment of your IT network.

News

TrustZone Kernel Privilege Escalation (CVE-2016-2431)

Qualcomm’s Secure Environment Operating System (QSEOS) provides services to the applications running under it by means of system-calls. In the “Secure World”, user-space applications can invoke system-call by issuing the “SVC” instruction. This means the operating system mustn’t trust any information provided by an application and should always validate it. In this blog post we’ll continue our journey from zero permissions to code execution in the TrustZone kernel. There are quite a few interesting things we can do solely from the context of this kernel. We could hijack any QSEE application directly, exposing all of it’s internal secrets.”]

Source: https://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Tracking wearable devices could be very easy via Bluetooth Low Energy

News

Social Networks Part 1 Who exactly are you disclosing your life story to?