Select your language

Critical vulnerability discovered in Qualcomm

International. A number of critical vulnerabilities in Qualcomm TrustZone that could lead to, among other things, leaks of protected data and the theft of mobile payment information and credentials, were exposed by cybersecurity company, Check Point Software Technologies Ltd.

This application is a security extension integrated by ARM in the Corex-A processor, which is an integral part of all modern Android mobile devices from brands such as Samsung, Xiaomi, Sony, Nexus, LG or HTC, among others. In fact, according to a study by Strategy Analytics, almost half of all smartphones in the world use Qualcomm processor technology.

For 4 months, Check Point has been analyzing the possible weaknesses of Qualcomm's "Safe World" operating system. To do this, the company's researchers used a technique known as "fuzzing", a method used to verify security levels and thus discover coding errors and security gaps in software, operating systems or networks. Through this technique, the company discovered 4 vulnerabilities in the trusted code implemented by Samsung (including some of the company's latest releases such as the S10), 1 in Motorola, 1 in LG, 1 related to LG, but all the code comes from Qualcomm.

What is TrustZone and why is it a critical vulnerability?
Qualcomm's TrustZone security extension creates an isolated and secure virtual environment that the operating system itself uses to provide confidentiality and integrity to the device. This environment is known as Trusted Execution Environment (TEE), and a vulnerability in this code is critical because it is responsible for providing security to the data stored on the device, and, in addition, has many execution permissions. In this way, if the integrity of the TEE is compromised, device failures such as data leaks, unlocking the bootloader or running undetectable APT can occur. In this way, an attacker could compromise the security of the terminal remotely and perform different malicious activities.

- Publicidad -

On the other hand, this vulnerability joins the recent cases that the company has experienced in recent months, in which Qualcomm warned that two of its processors for mobile devices had suffered security flaws that allowed attacking the smartphones of thousands of users and compromise the integrity of the Android operating system through access to the WLAN chip, also at a distance.

In this sense, Eusebio Nieva, check Point's technical director for Spain and Portugal, points out that "these types of vulnerabilities pose a serious risk to both devices and the personal information that users store on them. In addition, it is essential to bear in mind that, although phones are one of the most used devices in our day to day, there is a general tendency not to use protection measures, so through these vulnerabilities cybercriminals find a way to access a large amount of information. "

What can users do to protect themselves from this vulnerability?
From Check Point they warn about the fact that smartphones are one of the most unprotected devices, and point out the importance of becoming aware of the need to adopt a security strategy focused on ensuring the protection of the data they store.

In this sense, Qualcomm has already published a patch to solve this vulnerability, so the company's experts advise users of the terminals that incorporate Qualcomm TrustZone to update the operating system of the phone to the latest available version, as well as be attentive to any movement that is made using their credit or debit cards. In addition, from Check Point they recommend having a security tool that allows to examine the state of the mobile phone in search of possible threats such as malicious software and cryptojackers that have been installed on the device without the user knowing.

In this sense, the company has SandBlast Mobile, a solution that protects devices from infected applications, Man-in-the-Middle attacks over Wi-Fi, OS exploits, and malicious links in SMS messages.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter