Executive brief
OP-TEE is a secure operating system used on Arm-based processors to protect sensitive data and run trusted applications. A flaw in how the system verifies application signatures allows an attacker to bypass security updates and run older, potentially vulnerable versions of trusted software that were previously revoked. This could allow an attacker to re-introduce known security weaknesses into the secure environment, undermining the overall integrity of the device.
Technical details
A vulnerability exists in OP-TEE's subkey rollback protection mechanism due to improper authorization checks during the Trusted Application (TA) loading process. In `core/crypto/signed_hdr.c`, the function `shdr_load_pub_key()` fails to assign the `subkey_version` from the header to the runtime `shdr_pub_key` structure, leaving the version field at zero. Consequently, when `check_update_version()` is called, it receives a zeroed version, preventing the rollback database from advancing and allowing TAs signed with downgraded or revoked subkey chains to be accepted. An attacker with local access can exploit this to perform a downgrade attack, bypassing revocation and breaking the TA trust chain. The issue is fixed in version 4.11.0.
Affected products
- OP-TEE optee_os >= 3.20.0, < 4.11.0
Timeline
- 2026-03-30: other: Report received from Arm / Trusted Firmware
- 2026-03-31: other: Issue and severity confirmed
- 2026-06-30: patched: Fix published
- 2026-06-30: advisory: GitHub advisory published
- 2026-07-06: disclosed: NVD publication date