September 2024
Intermediate to advanced
408 pages
7h 29m
English
Wade (2021a) and Wade (2021b) document a memory corruption vulnerability in the bootloader of the PN553, PN547, PN548, PN551, and PN5180 series of NFC chips found in consumer smart-phones such as the Pixel 3 and Xiaomi MI Note 3. These implement NFC communications so that the operating system can call high-level abstractions. Raw control of the chip would be useful to perform raw NFC transactions, and that is the value of exploits for this vulnerability.
Within a phone, Wade found that Linux presents the device as /dev/nq-nci. This character device allows both standard NCI commands and custom commands unique to the series. Boot-loader commands were as follows, which he extracted from an ELF ...
Read now
Unlock full access