JUL 04 · 2025·1 min read

Fault-injecting a TrustZone secure monitor on the Allwinner T113-S3

The SoC vendor signs the secure-monitor blob but not the OP-TEE supplicant glue. A 12 ns brown-out on VDD_CPU at the SMC return reliably skips the capability check. Reading the eFuse OTP is then one syscall away.

Critical 9.4UNPATCHED

Full writeup coming soon.