Déjà Vu: Prevailing security vulnerabilities in TZ-assisted TEE systems

Joao do Sousa, David Cerdeira, Luís Cunha, Tiago Gomes, Bruno Crispo, Sandro Pinto · Journal of Systems Architecture · 2026

Trusted Execution Environments (TEEs) leveraging ARM TrustZone are widely deployed in mobile, IoT, and industrial devices. Nonetheless, vulnerabilities are still being discovered/reported on these systems, highlighting ongoing risks. In this paper, we extend prior research on TrustZone vulnerabilities for Application processors (TZ-A) by presenting a comprehensive reassessment of TrustZone-assisted TEEs, analyzing 520 bug reports between 2019 and mid-2026. We systematically examine vulnerabilities affecting major TrustZone TEE implementations, including those from major commercial providers, e.g., Qualcomm, Huawei, and Samsung. We concluded that despite years of research and mitigations, existing TEE implementations continue to be victims of the same architectural, implementation, and hardware issues reported in previous work. Furthermore, we provide clear evidence that these vulnerabilities have also been propagating into TrustZone-M (TZ-M) TEEs, exposing similar security issues in modern microcontroller (MCU) environments. Our findings, based on publicly disclosed CVEs, security bulletins, and academic studies, reiterate the urgent need for the industry to adopt stronger security techniques and mechanisms proposed by academic research as a fundamental step toward trustworthy commercial TEE implementations.

Read the paper · More papers on PaperTik