JUL 04 · 2025·1 min read
Fault-injecting a TrustZone secure monitor on the Allwinner T113-S3
The SoC vendor signs the secure-monitor blob but not the OP-TEE supplicant glue. A 12 ns brown-out on VDD_CPU at the SMC return reliably skips the capability check. Reading the eFuse OTP is then one syscall away.
Critical 9.4UNPATCHED
Full writeup coming soon.