CVE-2024-56187
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Published Mar 10, 2025
Updated: Mar 11, 2025
CWE ID 125
Summary
CVE-2024-56187 is a logic error vulnerability affecting the ppcfw_deny_sec_dram_access function in the ppcfw.c file. This issue allows for an arbitrary read from Trusted Execution Environment (TEE) memory. With System execution privileges required, local information disclosure can be achieved without user interaction. This vulnerability poses a significant risk for confidentiality breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android