TY - GEN
T1 - Overseer
T2 - 21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
AU - Suciu, Darius
AU - Pinjala, Sandeep Kiran
AU - Sun, Bin
AU - Sion, Radu
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/6/4
Y1 - 2026/6/4
N2 - TrustZone enables Rich Execution Environments (REEs) and Trusted Execution Environments (TEEs) to share physical memory by building virtual address spaces without knowing each other's mapping. While TEE hardware protection guarantees that the REE ("Normal World") is restricted to accessing non-secure memory exclusively, the Secure OS and Trusted Applications (TAs) operating within the TEE ("Secure World") can map physical memory belonging to REE OS and applications. As a result, vulnerabilities within TEE code, in conjunction with the inherent semantic gap between the REE and TEE can be leveraged by malicious actors to completely bypass REE security policies and leak or compromise REE-sensitive data or code. Our comprehensive analysis of TAs from commercial TrustZone devices and associated CVEs in the past decade has revealed numerous REE and TEE physical memory access vulnerabilities across multiple vendors. To mitigate the security impact of this critical semantic gap, we introduce Overseer, a secure monitor mechanism that prevents unauthorized physical memory mappings by TEEs, one of the important enablers of compromise. Overseer further enables the Secure OS and the TAs running inside the TEE to regulate the invocation of Secure Monitor Calls (SMCs) and System Calls. Overseer's performance overhead is under 2% on average. A detailed CVE analysis shows that Overseer can mitigate the attack surface of over 53 TA vulnerabilities.
AB - TrustZone enables Rich Execution Environments (REEs) and Trusted Execution Environments (TEEs) to share physical memory by building virtual address spaces without knowing each other's mapping. While TEE hardware protection guarantees that the REE ("Normal World") is restricted to accessing non-secure memory exclusively, the Secure OS and Trusted Applications (TAs) operating within the TEE ("Secure World") can map physical memory belonging to REE OS and applications. As a result, vulnerabilities within TEE code, in conjunction with the inherent semantic gap between the REE and TEE can be leveraged by malicious actors to completely bypass REE security policies and leak or compromise REE-sensitive data or code. Our comprehensive analysis of TAs from commercial TrustZone devices and associated CVEs in the past decade has revealed numerous REE and TEE physical memory access vulnerabilities across multiple vendors. To mitigate the security impact of this critical semantic gap, we introduce Overseer, a secure monitor mechanism that prevents unauthorized physical memory mappings by TEEs, one of the important enablers of compromise. Overseer further enables the Secure OS and the TAs running inside the TEE to regulate the invocation of Secure Monitor Calls (SMCs) and System Calls. Overseer's performance overhead is under 2% on average. A detailed CVE analysis shows that Overseer can mitigate the attack surface of over 53 TA vulnerabilities.
KW - Access Control
KW - ARM TrustZone
KW - Hardware Security
UR - https://www.scopus.com/pages/publications/105042424316
U2 - 10.1145/3779208.3807496
DO - 10.1145/3779208.3807496
M3 - Conference contribution
AN - SCOPUS:105042424316
T3 - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
SP - 743
EP - 758
BT - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
PB - Association for Computing Machinery, Inc
Y2 - 1 June 2026 through 5 June 2026
ER -