Get a Pentest and security assessment of your IT network.

News

TrustZone Kernel Privilege Escalation (CVE-2016-2431)

Qualcomm’s Secure Environment Operating System (QSEOS) provides services to the applications running under it by means of system-calls. In the “Secure World”, user-space applications can invoke system-call by issuing the “SVC” instruction. This means the operating system mustn’t trust any information provided by an application and should always validate it. In this blog post we’ll continue our journey from zero permissions to code execution in the TrustZone kernel. There are quite a few interesting things we can do solely from the context of this kernel. We could hijack any QSEE application directly, exposing all of it’s internal secrets.”]

Source: https://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

IntelCrawler profiled Syrian Electronic Army group

News

Wikileaks Vault 7 Imperial projects revealed the 3 hacking tools Achilles, SeaPea and Aeris