Google Pixel
cpe:2.3:h:google:pixel:*:*:*:*:*:*:*, +1 more
A logic error in the ppcfw_deny_sec_dram_access function of ppcfw.c creates a potential for arbitrary reading from Trusted Execution Environment (TEE) memory. This vulnerability could lead to local information disclosure, requiring system execution privileges for exploitation. User interaction is not necessary.
Exploitation of this vulnerability could result in unauthorized access to sensitive information stored in TEE memory.
Users can update their devices to the March 2025 security patch level to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.