Skip to finding
important · Boot chain

An unprivileged normal-world client can make OP-TEE sign an attacker-selected attestation digest.

Affects

OP-TEE Core, a trusted execution environment commonly used on Arm-based embedded and Linux systems.

The path requires local userspace access to the OP-TEE device interface and a build with CFG_ATTESTATION_PTA enabled.

Detail and 1 source

A verifier can accept the valid device signature as a false claim about OP-TEE or a trusted application.

OP-TEE has published a patch for the shared-buffer race.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026