usnistgov / mobile-threat-catalogue

NIST/NCCoE Mobile Threat Catalogue
https://pages.nist.gov/mobile-threat-catalogue
Other
142 stars 40 forks source link

New Threat: Loss of confidentiality to app process memory #254

Closed sdog-nist closed 6 years ago

sdog-nist commented 6 years ago

New Threat

Threat Category: STA

Threat: Based on recent Meltdown / Spectre threats, vulnerabilities in the CPU of a mobile device may permit a malicious application with escalated privileges to read the memory of running processes, allowing an attacker to obtain cryptographic keys and other secrets that are unencrypted in memory.

Threat Origin:

Exploit Example:

CVE Example:

Possible Countermeasures:

References: