Trust Issues: Exploiting TrustZone TEEs (Project Zero)
Here is alengthy and detailed look from Google's Project Zero at the trustedexecution environments that, one hopes, protect devices from compromise."In this blog post we'll explore the security properties of the twomajor TEEs present on Android devices. We'll see how, despite their highlysensitive vantage point, these operating systems currently lag behindmodern operating systems in terms of security mitigations andpractices. Additionally, we'll discover and exploit a major design issuewhich affects the security of most devices utilising bothplatforms. Lastly, we'll see why the integrity of TEEs is crucial to theoverall security of the device, making a case for the need to increasetheir defences."