<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Impalabs Blog</title>
        <link>https://blog.impalabs.com</link>
        <description>The Impalabs engineering blog is our privileged place to share our latest research in offensive security, vulnerability research and exploit development.</description>
        <language>en-us</language>
        <lastBuildDate>Thu, 21 Sep 2023 16:17:20 +0000</lastBuildDate>
        <atom:link href="https://blog.impalabs.com/feed.xml" rel="self" type="application/rss+xml"/>
<item>
    <title>Huawei TrustZone Block_Chain TA Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_block-chain.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Heap Pointer Leak in delete_node
- Memory Disclosure in bc_delete_file</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_block-chain.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone CHINADRM_COMMON_TA Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_chinadrm-common-ta.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Wrong memcpy_s Destination Sizes in CencDecrypt
- Lack of Locking when Accessing Global Variables
- Opening Sessions Before Initialization
- Session IDs Are Pointers</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_chinadrm-common-ta.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone CHINADRM_KEY_TA Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_chinadrm-key-ta.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- TEE_Param Output Buffer Overflow in TZ_CDRM_KeyPrivateKeyDecrypt</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_chinadrm-key-ta.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone Huawei_TSS_TA Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_huawei-tss-ta.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Stack Buffer Overflow in TA_GetPayload
- Heap Buffer Overflows and Stack Buffer Overreads in TA_DecryptSKWithCBC and TA_DecryptSKWithGCM
- Heap Buffer Overflow in TA_Gen_Sysintegrity_Jws
- Param Buffer Overread in TA_GetPayload
- Param Buffer Overread in TA_GetSysintegritySignStr
- Param Buffer Overread in TA_DecryptKEK
- Param Buffer Overread in hkdf_expand
- Limited Out of Bounds Accesses in CMD_TSS_GET_PKI_CERT and CmdVerifySignature</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_huawei-tss-ta.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone HuaweiNfcActiveCard Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_huaweinfcactivecard.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Buffer Overflow in SplitAidStrtok</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_huaweinfcactivecard.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone HW_KEYMASTER Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_hw-keymaster.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Write of Arbitrary Data to sec_storage_data/PKI/
- Write of Controlled Params Set in generate_keyblob
- Integer Overflow in ber_pop_front
- Stack Address Leak in cmd_verify_key
- Integer Overflow in ber_init
- Logic Issue in verify_root_cert
- Stack Buffer Overflow in get_soter_cpuid
- OOB Access in get_soter_cpuid</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_hw-keymaster.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone Ifaa Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ifaa.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Stack Buffer Overflow in parcel_read_ifaa_cert</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ifaa.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone IfaaKey_TA Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ifaakey-ta.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Parameter Pointers Information Leak in CmdSignWithCert</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ifaakey-ta.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TA_SignTool OOB Read</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_signtool.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- OOB Access in CmdInitObjectWithKeys</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_signtool.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TA_HuaweiWallet Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ta-huaweiwallet.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Incomplete Caller Verification
- Stack Buffer Overflow in GetCardALLByIndexV2
- Stack Buffer Overflow in genOffPayCodeSeedParam
- Stack Buffer Overflows in decodeCRSCert
- Heap Buffer Overflow in initPayCodeHead
- Heap Buffer Overread in isSamePayCodeSeed
- Heap Buffer Overread in transferV1ToV2Paycode
- OOB Accesses in CmdWalletGenPayCodeSeedParam
- OOB Accesses in CmdWalletSavePayCodeSeed
- OOB Accesses in CmdWalletSetPayCodeAuthInfo
- OOB Accesses in CmdWalletGetTrafficPayCode
- OOB Accesses in CmdWalletGetFinancePayCode
- OOB Accesses in CmdWalletVerifyPayCodeAuthInfo
- OOB Access in SendSetStatusCmd
- Param Buffer Overflow in CmdWalletGetCardByIndex
- Param Buffer Overreads in CmdWalletApplyEnableAndDisableCardToI2C
- Param Buffer Overreads in CmdWalletActivateCardByBiometricsId
- Param Buffer Overreads in CmdWalletVerifySwipeCard</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ta-huaweiwallet.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TA_SensorInfo Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ta-sensorinfo.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Multiple TEE_Param Pointer Leaks in TA_InvokeCommandEntryPoint</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ta-sensorinfo.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TA_uDFingerPrint Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ta-udfingerprint.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Param Buffer Overflow in TA_fp_tee_get_indices
- Code Pointer Leak in lib_sync_sensor_info
- Lack of Locking when Accessing Global Variables</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_ta-udfingerprint.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TALoader Information Leak</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_taloader.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Generic ASLR Bypass Using TALoader's Information</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_taloader.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone Task_Phone_Novelchd Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_task-phone-novelchd.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Missing Length Checks in GetOCSPResponse
- Missing Length and Offset Checks in NOVEL_CHDRM_Copyordecrypt
- Missing Length Checks in NOVEL_CHDRM_SetDRMCertData
- Missing Length Check in DRM_Secure_Store_Read
- Missing Length Check in getvaluewithtypeandindex
- Missing Length Checks in Secure_Store_EncryptWrite and Secure_Store_PlainWrite
- Missing Length Checks in NOVEL_CHDRM_SetRegisterResData
- Missing / Faulty Length Checks When Calling NOVEL_CHDRMw_MemCompare
- Integer Underflow in find_tlv_data
- OOB Accesses in getvaluewithtypeandindex
- Unchecked Malloc Return Values
- Missing Length Check in pack_tlv_data
- Missing Length Checks After Calling unpack_tlv_data
- Stack / Heap / BSS Pointer Leaks in DRM_AES_Encrypt_xxx
- Integer Underflow in unpack_tlv_data</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_task-phone-novelchd.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TCIS Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tcis.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Heap Pointer Leak in AuthAckSlave</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tcis.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TEE_EID Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-eid.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- OOB Access in the Encap_tlv_for_hash_zip Function
- OOB Access in the get_sec_image_zip Function
- Parameter Pointers Information Leak in the check_xxx_params Functions
- Heap Pointers Information Leak in the eid_malloc, eid_free, malloc_eid_buffer and free_eid_buffer Functions</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-eid.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone Tee_Fido_Main Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-fido-main.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Stack Buffer Overflow in UnwrapKeyHandle</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-fido-main.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TEE_SERVICE_FACE_REC Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-service-face-rec.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Unverified Param Types in FI_onExec
- OOB Write in HiAiManager::loadModelFromBuffers
- Integer Overflow in FR_TA_CoAuthSignImg
- Param OOB Access in FI_onExec
- Null Pointer Dereference in MsgController::_sendMsg
- Physical Address Leak in the Trustlet Function FR_TA_CoAuthSignImg
- Param Pointer Leak in the Trustlet Function FR_GetHwAuthToken
- Param Pointer Leaks in the Trustlet Function FR_ActiveUserSet
- ION Virtual Address Leak in the Trustlet Function FR_HashCheck
- Param Pointer Leak in the Trustlet Function FR_GetResultAuthToken
- Heap Pointer Leak in the Trustlet Function FR_LoadDataBase
- Heap Pointer Leak in the Trustlet Function FR_FaceFeatureAdd
- Param Pointer Leaks in the Trustlet Function FR_SetFidoParam
- Stack Pointer Leak in the Trustlet Function FidoWrapUvt
- Heap Pointer Leaks in the Trustlet Function FR_UnwrapFeatureData
- Heap Pointer Leak in the Library Function AlgoManager::createAlgo
- ION Virtual Memory Address Leak in the Library Function HiAiManager::loadModelFromBuffers
- ION Physical Memory Leak in the Library Function HiAiManager::runModelInMainThread
- ION Virtual Memory Address Leak in the Library Function HiAiManager::loadModelFromBuffers
- ION Virtual Memory Address Leak in the Library Function MemoryManager::alloc
- ION Virtual Memory Address Leak in the Library Function MemoryManager::free
- Pointer Leak in the Library Function MsgController::agentLock
- Heap Pointer Leak in the Library Function CImageBufferAllocator::endAllocatation
- Heap Pointer Leak in the Library Function CImageBufferAllocator::endAllocatation
- Heap Pointer Leak in the Library Function CImageBufferAllocator::beginAllocatation
- Pointer Leak in the Library Function CImageBuffer::delStride
- Heap Pointer Leak in the Library Function CImageBuffer::fillImage
- Pointer Leak in the Library Function CImageBuffer::attachBuffer
- Pointer Leak in the Library Function ImageSourceBase::clear
- Heap Pointer Leaks in the Library Function PipelineBuilder::createPipeline
- ION Virtual Addresses Leaks in the Library Function STFaceidAlgo::loadCpuModel
- ION Virtual Address and Heap Pointer Leak in the Library Function hw_face_quality_estimation
- Heap Pointer Leaks in the Library Function buffered_free
- ION Virtual Memory Address Leak in the Library Functionst_tee_initialize
- Heap Pointer Leak in the Library Function st_tee_detect
- Heap Pointer Leak in the Library Function st_tee_extract
- Stack Pointer and ION Virtual Address Leaks in the Library Function st_tee_create_handle
- Heap Pointer Leaks in the Library Function gray16to8_hist
- Virtual Address Leak in the Library Function HIAI_TensorBuffer_createFromTensorDesc
- ION Virtual Memory Address Leak in the Library Function HIAI_ModelManager_loadFromModelBuffers
- Stack and Heap Pointer Leak in FR_AloEnroll
- Faulty check in GetPlainDataWhenEnroll</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-service-face-rec.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TEE_SERVICE_MULTIDRM Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-service-multidrm.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Heap Buffer Overflow in MDrm_TA_CMD_OEMCrypto_LoadKeys
- Heap Buffer Overflow in MDrm_TA_CMD_OEMCrypto_LoadEntitledContentKeys
- Heap Buffer Overflow in MDrm_TA_CMD_OEMCrypto_RefreshKeys
- Heap Buffer Overflow in MDrm_TA_OEMCryptoUsageTable_LoadUsageTableHeader
- OOB Write access in MDrm_TA_CMD_OEMCrypto_CopyBuffer
- OOB Read Access in MDrm_TA_CMD_Provision_GetRequest
- OOB Read Access in MDrm_TA_CMD_OEMCrypto_RewrapDeviceRSAKey30
- OOB Read Access in MDrm_TA_CMD_OEMCrypto_DecryptCENC</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-service-multidrm.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TEE_SERVICE_VOICE_REC Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-service-voice-rec.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- OOB Access in DecryptData
- Heap Buffer Overflow in SendTaGmmBuf
- OOB Access in restore
- Information Leak in compare
- Information Leak in restore
- Null Pointer Dereference in CheckModelHash</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-service-voice-rec.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone TEE_Weaver Vulnerability</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-weaver.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Missing Input Parameters Check in InterfaceRead</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_tee-weaver.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone VprTa Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_vprta.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- IsGmmModelLoaded OOB Access
- InitGetScoreParams OOB Access
- GmmGetScore OOB Access
- OOB Access in LTopProb
- Param Buffer Overflow in XvectorLoadModels
- Param Buffer Overread in InitGetScoreParams</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_vprta.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei TrustZone Vsim_Sw Vulnerabilities</title>
    <link>https://blog.impalabs.com/2309_advisory_huawei_trustzone_vsim-sw.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Limited Arbitrary Function Call in TA_InvokeCommandEntryPoint
- Integer Overflows in VSIM_CmdSaveAllMaincard
- Stack Buffer Overflows in VsimSaveOpiMainParam, VsimSaveOpiSlaveParam and VsimModemSendDhVsimData
- Param Buffer Overread in GenerateMasterMsg
- Param Buffer Overflow in VsimEncryptoString</description>
    <guid>https://blog.impalabs.com/2309_advisory_huawei_trustzone_vsim-sw.html</guid>
    <pubDate>Tue, 19 Sep 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Parallels Desktop Toolgate Vulnerability</title>
    <link>https://blog.impalabs.com/2303_advisory_parallels-desktop_toolgate.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- Directory Traversal Arbitrary File Write Vulnerability</description>
    <guid>https://blog.impalabs.com/2303_advisory_parallels-desktop_toolgate.html</guid>
    <pubDate>Mon, 20 Mar 2023 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei Secure Monitor Vulnerabilities</title>
    <link>https://blog.impalabs.com/2212_advisory_huawei-secure-monitor.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- SMC SE Factory Check OOB Access
- SMC MNTN OOB Access (Integer Overflow)
- SMC MNTN OOB Access (Shared Control Structure)</description>
    <guid>https://blog.impalabs.com/2212_advisory_huawei-secure-monitor.html</guid>
    <pubDate>Tue, 13 Dec 2022 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Huawei Security Hypervisor Vulnerability</title>
    <link>https://blog.impalabs.com/2212_advisory_huawei-security-hypervisor.html</link>
    <description>This advisory contains information about the following vulnerabilities:
- OOB Accesses Using the Logging System</description>
    <guid>https://blog.impalabs.com/2212_advisory_huawei-security-hypervisor.html</guid>
    <pubDate>Thu, 01 Dec 2022 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Shedding Light on Huawei's Security Hypervisor</title>
    <link>https://blog.impalabs.com/2212_huawei-security-hypervisor.html</link>
    <description>All recent Huawei devices ship with a security hypervisor, a defense-in-depth measure designed to enhance kernel security. Unlike other OEMs, Huawei encrypts this privileged piece of software, hence why it has received little to no public scrutiny. With this blog post, we aim to cast light on its inner-workings and provide an in-depth analysis of its implementation, from its entry point to the functions dedicated to protecting the kernel at runtime.</description>
    <guid>https://blog.impalabs.com/2212_huawei-security-hypervisor.html</guid>
    <pubDate>Thu, 01 Dec 2022 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Hyperpom: An Apple Silicon Fuzzer for 64-bit ARM Binaries</title>
    <link>https://blog.impalabs.com/2211_hyperpom.html</link>
    <description>Impalabs is releasing Hyperpom, a 64-bit ARM binary fuzzer written in Rust and based on the Apple Silicon's hypervisor. It is mutation-based and coverage-guided. This article gives an overview of its internals, presents the different components it consists of and how they relate to each other. Most importantly, it also gathers all the resources you need to get started and begin fuzzing your own 64-bit ARM targets.</description>
    <guid>https://blog.impalabs.com/2211_hyperpom.html</guid>
    <pubDate>Tue, 15 Nov 2022 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Attacking Samsung RKP</title>
    <link>https://blog.impalabs.com/2111_attacking-samsung-rkp.html</link>
    <description>This is a follow-up to our compendium blog post that presented the internals of Samsung's security hypervisor, including all the nitty-gritty details. This extensive knowledge is put to use in today's blog post that explains how we attacked Samsung RKP. After revealing three vulnerabilities leading to the compromise of the hypervisor or of its assurances, we also describe the exploitation paths we came up with. Finally, we take a look at the patches made by Samsung following our report.</description>
    <guid>https://blog.impalabs.com/2111_attacking-samsung-rkp.html</guid>
    <pubDate>Thu, 25 Nov 2021 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Reversing and Exploiting Samsung's NPU (Part 2)</title>
    <link>https://blog.impalabs.com/2110_exploiting-samsung-npu.html</link>
    <description>After an in-depth analysis of the NPU OS and its interaction with the Android kernel, this second part gives a more offensive outlook on this component. We will go through the main attack vectors to target it and detail two vulnerabilities that can be chained together to get code execution in the NPU from the NPU driver before pivoting back into the kernel.</description>
    <guid>https://blog.impalabs.com/2110_exploiting-samsung-npu.html</guid>
    <pubDate>Mon, 25 Oct 2021 00:00:00 -0000</pubDate>
</item>
<item>
    <title>Reversing and Exploiting Samsung's NPU (Part 1)</title>
    <link>https://blog.impalabs.com/2103_reversing-samsung-npu.html</link>
    <description>This series of blog posts aims to describe and explain the internals of a recent addition to Samsung's system-on-chips, namely their Neural Processing Unit. The first part digs into the internals of the NPU and the second one focuses on the exploitation of some vulnerabilities we found in the implementation. If you're interested in reversing a minimal OS, want to understand how Android interacts with peripherals and do exploitation like it's the early 2000's, this series might be for you.</description>
    <guid>https://blog.impalabs.com/2103_reversing-samsung-npu.html</guid>
    <pubDate>Wed, 24 Mar 2021 00:00:00 -0000</pubDate>
</item>
<item>
    <title>A Samsung RKP Compendium</title>
    <link>https://blog.impalabs.com/2101_samsung-rkp-compendium.html</link>
    <description>The purpose of this blog post is to provide a comprehensive reference of the inner workings of the Samsung RKP. It enables anyone to start poking at this obscure code that is executing at a high privilege level on their device. In addition, a now-fixed vulnerability that allowed getting code execution in Samsung RKP is revealed. It is a good example of a simple mistake that compromises platform security, as the exploit consists of a single call, which is all it takes to make hypervisor memory writable from the kernel.</description>
    <guid>https://blog.impalabs.com/2101_samsung-rkp-compendium.html</guid>
    <pubDate>Mon, 04 Jan 2021 00:00:00 -0000</pubDate>
</item>
    </channel>
</rss>