Op Tee · Op-Tee · CVE-2026-53763
**Name of the Vulnerable Software and Affected Versions**
OP-TEE versions 3.0.0 through 4.10.x
**Description**
OP-TEE is a Trusted Execution Environment (TEE) designed as a companion to a non-secure Linux kernel running on Arm Cortex-A cores using TrustZone technology. A 32-bit integer overflow exists in the AES-GCM implementation of the OP-TEE core. This issue occurs when processing more than 512 megabytes of payload or Additional Authenticated Data (AAD), causing the authentication tag to be computed with incorrect bit-length values and breaking the authentication guarantee.
**Recommendations**
Update to version 4.11.0.