Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://www.qualcomm.com/company/product-security/bulletins | vendor advisory |
http://www.securitytracker.com/id/1041432 | vdb entry third party advisory |
https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components | third party advisory |