Qualcomm Critical Flaw Exposes Private Keys For Android Devices
#1
Quote:A side-channel attack in Qualcomm technology, which is used by most modern Android devices, could allow an attacker to snatch private keys.

Researchers have uncovered a side-channel attack that enables a bad actor to extract sensitive data from Qualcomm’s secure keystore. The critical flaw impacts most modern Android devices that use Qualcomm chips.

The issue stems from an issue in Qualcomm technology, dubbed the Qualcomm Secure Execution Environment (QSEE), designed to guard cryptographic keys on devices. As a result of exploiting the flaw, attackers can pluck “sensitive data,” including private encryption keys, passwords and more, from Qualcomm-powered devices.
 
“Recent Android devices include a hardware-backed keystore, which developers can use to protect their cryptographic keys with secure hardware,” according to NCC Group consultant Keegan Ryan, who discovered the attack, in a Tuesday post. “On some devices, Qualcomm’s TrustZone-based keystore leaks sensitive information through the branch predictor and memory caches, enabling recovery of 224 and 256-bit ECDSA [Elliptic Curve Digital Signature Algorithm] keys.”

SOURCE: https://threatpost.com/qualcomm-critical...id/144112/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Adlice Protect (formerly RogueKiller) 16...
Adlice Protect (fo...harlan4096 — 10:41
Brave 1.84.132
Release Channel 1....harlan4096 — 10:40
uBOLite 2025.1028.1744
uBOLite 2025.1028....harlan4096 — 10:38
AMD confirms Zen6 Ryzen “Medusa” CPUs du...
AMD Venice and Med...harlan4096 — 10:34
AMD Radeon Software Adrenalin 25.10.2 dr...
Highlights  New...harlan4096 — 10:33

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>