Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-33232 Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Samsung Mobile

Published:

Updated: 2024-08-03T06:03:52.587Z

Reserved: 2022-04-07T00:00:00

Link: CVE-2022-28793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-03T20:15:09.803

Modified: 2024-11-21T06:57:56.790

Link: CVE-2022-28793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.