VYPR
Unrated severityNVD Advisory· Published Jun 26, 2023· Updated Dec 4, 2024

CVE-2022-48333

CVE-2022-48333

Description

Integer overflow in Widevine TA drm_verify_keys leads to a buffer overflow, enabling code execution from the Normal World on Android devices.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer overflow in Widevine TA drm_verify_keys leads to a buffer overflow, enabling code execution from the Normal World on Android devices.

Vulnerability

The Widevine Trusted Application (TA) in Qualcomm's Secure Execution Environment (QSEE), versions 5.0.0 through 5.1.1, has an integer overflow in the drm_verify_keys function (offset 0x730c). The overflow occurs when computing prefix_len + feature_name_len, leading to insufficient buffer allocation and a subsequent heap-based buffer overflow. The vulnerability is reachable by sending a crafted command from the Normal World to the TA. Affected builds include Nexus 6 firmware versions LRX21O through LMY48M [1].

Exploitation

An attacker with the ability to communicate with the Widevine TA from the Normal World (e.g., via the QSEE driver from userspace, requiring no prior Android privilege) can trigger this bug. The attacker sends a malicious drm_verify_keys command with specially crafted prefix_len and feature_name_len values causing the integer overflow. The sequence does not require user interaction or physical access, only local execution as an unprivileged Android process [1].

Impact

Successful exploitation results in a buffer overflow in the secure world (QSEE), potentially allowing arbitrary code execution within the Widevine TA. This can lead to full compromise of the DRM-protected content flow, elevation of attacker privileges to the TEE level, and disclosure or manipulation of sensitive key material. The attacker gains the ability to dump cryptographic keys and execute arbitrary code at the TrustZone secure level [1].

Mitigation

Google addressed this vulnerability in the Android security bulletin. Users should apply the latest OTA updates for Nexus 6 devices (patched in firmware builds beyond LMY48M). No interim workaround is available, as the fix requires updating the Widevine TA image. The affected firmware versions are now end-of-life, but the vendor has released the patch. This CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Widevine/Widevine Trusted Application (TA)description
  • Range: 5.0.0 - 5.1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.