
A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices
Introduction to Trusted Execution Environment: ARM's TrustZone
Introduction to TEE (original title: TEEを中心とするCPUセキュリティ機能の動向 )
Attacking the ARM's TrustZone
ARM TrustZone Security Whitepaper
Web Site ARM TrustZone
TrustZone Explained: Architectural Features and Use Cases
Trustworthy Execution on Mobile Devices
Demystifying ARM Trustzone : A Comprehensive Survey
Understanding Trusted Execution Environments and Arm TrustZone (by Azeria)
SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE Systems
Giving Mobile Security the Boot (by Jonathan Levin)
The ARMs race to TrustZone (by Jonathan Levin)
Exploiting Trustzone on Android (BH-US 2015) by Di Shen(@returnsme)
EL3 Tour : Get the Ultimate Privilege of Android Phone (Infiltrate19)
Nailgun: Break the privilege isolation in ARM devices (PoC #2 only)
Nick Stephens : how does someone unlock your phone with nose. (give big picture of NWd <> SWd communications and exploits) GeekPwn 2016
Reflections on Trusting TrustZone (2014)
Getting arbitrary code execution in TrustZone's kernel from any context (28/03/2015)
Exploring Qualcomm's TrustZone implementation (04/08/2015)
Full TrustZone exploit for MSM8974 (10/08/2015)
TrustZone Kernel Privilege Escalation (CVE-2016-2431)
War of the Worlds - Hijacking the Linux Kernel from QSEE
QSEE privilege escalation vulnerability and exploit (CVE-2015-6639)
Exploring Qualcomm's Secure Execution Environment (26/04/2016)
Android privilege escalation to mediaserver from zero permissions (CVE-2014-7920 + CVE-2014-7921)
Trust Issues: Exploiting TrustZone TEEs (24 July 2017)
Breaking Bad. Reviewing Qualcomm ARM64 TZ and HW-enabled Secure Boot on Android (4-9.x)
Technical Advisory: Private Key Extraction from Qualcomm Hardware-backed Keystores CVE-2018-11976 (NCC)
Qualcomm TrustZone Integer Signedness bug (12/2014)
The road to Qualcomm TrustZone apps fuzzing (RECON Montreal 2019)
Downgrade Attack on TrustZone
Unbox Your Phone: Parts I, II & III
KINIBI TEE: Trusted Application Exploitation (2018-12-10)
TEE Exploitation on Samsung Exynos devices by Eloi Sanfelix: Parts I, II, III, IV
Breaking Samsung's ARM TrustZone (BlackHat USA 2019)
Launching feedback-driven fuzzing on TrustZone TEE (HITBGSEC2019)
A Deep Dive into Samsung's trustzone
Breaking TEE Security :
Reverse-engineering Samsung Exynos 9820 bootloader and TZ by @astarasikov
Bug Hunting S21’s 10ADAB1E FW (OffensiveCon 2022)
Learning from the old Samsung Exynos Trustlet bug by @TwizzyIndy