Qualcomm TZ Firmware Improper Access Control Vulnerability Allowing Key Register Read

Vulnerability

A cryptographic vulnerability has been identified in the TrustZone (TZ) firmware of various chipsets, including those used in Snapdragon 8 Gen 1 and 8 Gen 2 mobile platforms, as well as several other Qualcomm platforms. The vulnerability arises from an access control misconfiguration that allows the Linux operating system to read key registers in the TrustZone Control and Status Register (TCSR), potentially leading to unauthorized information disclosure or manipulation.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive cryptographic keys or information, allowing for potential manipulation of cryptographic operations or data.

Remediation

Qualcomm has developed patches for this vulnerability, which are available through the Qualcomm Update Catalog. Instructions for applying the patch can be obtained from the device manufacturer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.7
impact
2.5
exploitability
3.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.