Google Pixel Devices LDFW Component Information Disclosure Vulnerability

Vulnerability

A logic error in the ppcfw_deny_sec_dram_access function of ppcfw.c creates a potential for arbitrary reading from Trusted Execution Environment (TEE) memory. This vulnerability could lead to local information disclosure, requiring system execution privileges for exploitation. User interaction is not necessary.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information stored in TEE memory.

Remediation

Users can update their devices to the March 2025 security patch level to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
2.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.