CVE-2026-102709: Infoleak
Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already be able to execute code in the TrustZone-M non-secure world. The issue is exposed through affected non-secure callable entry functions in secure firmware.
What does exploitation require?
The attacker supplies pointers that reference secure memory to NSC entry functions. Exploitation succeeds when the secure firmware dereferences those pointers without validating that they point to non-secure memory.
What is the potential impact beyond information disclosure?
The described behavior can disclose secure-memory contents, including potentially sensitive cryptographic material. It may also provide a memory-corruption primitive, depending on how the affected secure firmware uses the attacker-controlled pointers.