Unrestricted read/write access to secure (TEE) memory (and code execution) due to logic issue in secure sysmmu pagetable protection on Google Pixel 6
Details
In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.