Soft Spots in Hard Tech: Mobile Security Challenges in Web3
ID: f1b803f9-67bf-5d2b-9665-707bb6fe389e
STIX ID: report--f1b803f9-67bf-5d2b-9665-707bb6fe389e
Feed Name: CertiK Blog
Researchers found two serious security weaknesses in a popular Web3-focused smartphone: an unlocked/weak bootloader that could let an attacker install custom firmware and a TEE implementation flaw that allowed extraction of the wallet PIN and private keys; both risks could enable complete compromise of users' plaintext data and crypto assets, were responsibly disclosed to vendors, and the TEE issue has been fixed, with recommendations for stronger hardware and supply-chain protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
