Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Samsung Mobile

Published: 2022-05-03T19:44:08

Updated: 2022-05-03T19:44:08

Reserved: 2022-04-07T00:00:00


Link: CVE-2022-28793

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-03T20:15:09.803

Modified: 2022-05-11T17:56:00.663


Link: CVE-2022-28793

JSON object: View

cve-icon Redhat Information

No data.

CWE