Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Samsung Mobile

Published: 2022-05-03T19:44:08

Updated: 2024-08-03T06:03:52.587Z

Reserved: 2022-04-07T00:00:00

Link: CVE-2022-28793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-03T20:15:09.803

Modified: 2022-05-11T17:56:00.663

Link: CVE-2022-28793

cve-icon Redhat

No data.