CVE-2026-53763

LOW CVSS 3.0: 3.8 EPSS 0.19%
Updated Jul 07, 2026
Trustedfirmware
Parameter Value
CVSS 3.8 (LOW)
Affected Versions 3.0.0 — 4.10.0
Type CWE-190 (Integer Overflow)
Vendor Trustedfirmware
Public PoC No

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM implementation cause the authentication tag to be computed with incorrect bit-length values after processing more than 512 megabytes of payload or Additional Authenticated Data (AAD). Version 4.11.0 contains a patch.

No known workarounds are available.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Trustedfirmware Op-Tee
cpe:2.3:o:trustedfirmware:op-tee:*:*:*:*:*:*:*:*
3.0.0 <= 4.10.0