USENIX Security2024Top-tier venue
Spill the TeA: An Empirical Study of Trusted Application Rollback Prevention on Android Smartphones
Marcel Busch, Philipp Mao, Mathias Payer
Abstract
The number and complexity of Trusted Applications (TAs, applications running in Trusted Execution Environments-TEEs) deployed on mobile devices has exploded. A vulnerability in a single TA impacts the security of the entire device. Thus, vendors must rapidly fix such vulnerabilities and revoke vulnerable versions to prevent rollback attacks, i.e., loading an old version of the TA to exploit a known vulnerability. In this paper, we assess the state of TA rollback prevention by conducting a large-scale cross-vendor study. First, we establish the largest TA dataset in existence, encompassing 35,541 TAs obtained from 1,330 firmware images deployed on mobile devices across the top five most common vendors. Second, we identify 37 TA vulnerabilities that we leverage to assess the state of industry-wide TA rollback effectiveness. Third, we make the counterintuitive discovery that the uncoordinated usage of rollback prevention correlates with the leakage of security-critical information and has far-reaching consequences potentially negatively impacting the whole mobile ecosystem. Fourth, we demonstrate the severity of ineffective TA rollback prevention by exploiting two different TEEs on fully-updated mobile devices. In summary, our results indicate severe deficiencies in TA rollback prevention across the mobile ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext af97dcbe-2740-4b7e-809d-3e1893ffe1e7Cited by top-tier papers2
- GlobalConfusion: TrustZone Trusted Application 0-Days by DesignMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 4 citations
- TÄMU: Emulating Trusted Applications at the (GlobalPlatform)-API LayerPhilipp Mao, Li Shi, Marcel Busch, Mathias PayerS&P 2026 · 1 citation
Builds on11
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 231 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- BOOMERANG: Exploiting the Semantic Gap in Trusted Execution EnvironmentsAravind Machiry, Eric Gustafson, Chad Spensky, Christopher Salls et al.NDSS 2017 · 119 citations
- Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps' Native CodeSumaya Almanee, Arda Ünal, Mathias Payer, Joshua GarciaICSE 2021 · 20 citations
Related papers
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu et al.ICSE 2022 · 21 citations
- Rollbaccine: Herd Immunity against Storage Rollback Attacks in TEEsDavid C. Y. Chu, Aditya Balasubramanian, Dee Bao, Natacha Crooks et al.SIGMOD 2026 · 6 citations
- HarborMaster: Rollback Detection for Trusted Distributed ComputingShubham Mishra, Alexander Thomas, Nurzhan Abdrassilov, Kaiyuan Chen et al.VLDB 2026
- TEEzz: Fuzzing Trusted Applications on COTS Android DevicesMarcel Busch, Aravind Machiry, Chad Spensky, Giovanni Vigna et al.S&P 2023
- Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device FingerprintingMichael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma et al.CCS 2025
