Detecting Qualcomm CPU errors can cause private data on the phone to leak
Security researchers from the Check Point Research team have revealed a series of dangerous vulnerabilities that appear on Qualcomm chipsets that allow attackers to steal important personal information of smartphone owners, along with a series of other risks related to rooting, unlocking bootloader and executing unknown APTs .
Qualcomm immediately confirmed the situation and worked with OEMs to issue patches in the form of system updates. Samsung and LG have applied patches to their devices, while Motorola is said to have fixed the problem.
Basically, Qualcomm CPUs often come with a secure area inside the processor called the Trusted Execution Environment (TEE). TEE's mission is to ensure the confidentiality and integrity of code and data based on ARM TrustZone technology - allowing the storage of the most sensitive data without risk of tampering.
In addition, this 'security world' provides some additional services in the form of trusted third-party components (also known as trustlets) that are loaded and executed in TEE by the operating system running in TrustZone - called the trusted OS (trusted OS).
Trustlets will act as a bridge between the 'normal' world - the rich execution environment where the device's main operating system (e.g. Android) exists - and the TEE, thereby enabling Move data between two 'worlds'.
TrustZone will be a place for important data such as passwords, credit card information for mobile payments, encryption keys and more. Thus, if a hacker invades this area through a vulnerability, nothing will prevent your sensitive data from being stolen.
Qualcomm said that without access to the hardware keys of the device, you would not be able to access data stored in QTEE unless there was a flaw in which the keys were exposed. And this is exactly the problem that Qualcomm chipset is having.
To find this flaw, Check Point researchers used a technique called fuzzing - an automated testing method that involves providing random data as input to a computer program to causing it to crash, thereby identifying undesirable programming behaviors and errors that can be exploited to provide corrective measures.
According to research results, vulnerabilities on Qualcomm CPUs could allow an attacker to execute applications in the 'normal world', load an application into a 'security world' and even load trustlets from another device.
There have not been any actual attacks recorded, the prospects for crooks to exploit these holes are huge. Attacks on TrustZone are a way to gain access to protected data on mobile devices. And such an attack will be used as part of an exploit chain starting from installing a malicious application to a device or spreading through a malicious link.
You should read it
- Snapdragon 865 pitted A13 Bionic: 'One more pain' for the Qualcomm team
- Qualcomm's $ 2 billion 5G network project will be available on Lenovo, Oppo, Vivo and Xiaomi phones
- 5 things to know about Qualcomm Snapdragon 845 chip
- The real thing behind Xiaomi, OPPO, and Vivo is against Broadcom's acquisition of Qualcomm
- Google revealed a critical flaw in Qualcomm's Adreno GPU
- Broadcom wants to buy Qualcomm with an unprecedented 130 billion dollar deal
- Compare the size of high-end chips from Qualcomm, Samsung, Huawei and Apple
- Google and LG do not want to buy Snapdragon 865 from Qualcomm because the price is too expensive
May be interested
- How to check and fix DNS leak error in VPNwhen using a secure connection like a vpn tunnel, a dns leak error occurs when dns requests are sent over a normal (unencrypted) network instead of a secure tunnel.
- DeepSeek Suffers Data Leakif you tried using deepseek this week, be aware that your chat data may have been leaked.
- Apple considers removing Qualcomm chips on iPhones and iPads next yearamidst escalating tension on legal issues of qualcomm, the wall street journal said apple is designing 2018 iphone and ipad models without qualcomm lte chips.
- Qualcomm announces new 4G chipset series: Snapdragon 720G, 662, and 460, what's noteworthy?qualcomm has launched a series of three new mobile cpu platforms aimed at the mid-range and mainstream segments.
- 26 billion users' personal records exposed in the biggest leak on the Internetaccording to reports from security consulting companies security discovery and cyber news, a data warehouse of up to 12 terabytes containing 26 billion personal records of weibo, twitter, linkedin, zing... users was leaked.
- 773 million emails, 21 million passwords were revealed on the Internet, this is the largest personal data leak in history772.904,991 emails and 21,222,975 user passwords have been shared publicly on the internet. this is the largest data leak by scale and is named collection # 1.
- Detects 540 million Facebook user data publicly stored on Amazon serversthe data set of the colectiva cultura has a total of 146 gb, including 540 million facebook user record records.
- How have 50 million Facebook users been taken advantage of by Cambridge Analytica to serve politics?in facebook's data leak, the algorithm used has scooped up almost all of the user's personal information, even sensitive information such as sexual orientation, intelligence and mental damage. from childhood through the like buttons that facebook users still use.
- Google Pixel 5 may not use Qualcomm's top processora report says that google will be using a lower-cost chip to power its next phone.
- How to enable password leak detection on Chromepassword leak detection on chrome is a security feature that notifies users if any passwords are at risk of being leaked or in a data breach.