CVE-2026-102709
— UNSCOREDpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.
Weaknesses
CWE-200, CWE-501, CWE-822
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-100241
- UNSCOREDCVE-2026-100244
- MEDIUMCVE-2026-100286
- UNSCOREDCVE-2026-100377
- UNSCOREDCVE-2026-100379PoC
- MEDIUMCVE-2026-100418PoC
- MEDIUMCVE-2026-100528PoC
- HIGHCVE-2026-100543PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.