Impact
Secure BootROM of the RK3588s SoC contains a TOCTOU flaw that allows an attacker to trick the bootloader into accepting modified modules. The bug lies in the two‑stage header read: a partial read supplies hashes, while a subsequent full read supplies signatures, yet the module authenticity check uses the partial data. An attacker with physical access can swap the header data on external media, causing the bootloader to load malicious code with EL3 privileges. This leads to total compromise of the device.
Affected Systems
Affected hardware is the Rockchip RK3588s system‑on‑chip, specifically the Secure BootROM version 350B20210512V100. The flaw may also exist in other boot ROM revisions of the RK3588s family. Any device running this SoC and booting from external media (SPI NOR, NAND, eMMC, SD) is affected.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. The EPSS score is not available, so overall exploitation likelihood cannot be quantified, but the vector demonstrates that only physical access to a device that boots from removable media is required. Because the vulnerability allows execution of code at level‑3 privileges, the impact is critical. The flaw is not listed in CISA KEV, suggesting no publicly available exploits yet, yet its simplicity and low cost of attack hardware make it a high priority for remediation.
OpenCVE Enrichment