I managed to internally use HeapSnitch (modified) vulnerability in QSEE to extract UDS
As you may know Google has previously revoked this, but they reincarnated it again, and during my experiments, i figured that BCC it had did NOT involve TME or CE, and was self signed, and placed directly for S-EL0 signing.
This is critical, we expected at least that it's a leaf derivation from TME.
MediaTek claims spot 2 now that NSW-EL0 can do this on QSEE.
This came as a challenge because I've been rumored that some managed to do the same and even for StrongBox.
Post #312
2.75K
- 🔥 24
- ❤ 4
- 👍 1