<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Privilege-Escalation on +5 Security Research</title><link>https://overkazaf.github.io/blogs/tags/privilege-escalation/</link><description>Recent content in Privilege-Escalation on +5 Security Research</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Sat, 09 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://overkazaf.github.io/blogs/tags/privilege-escalation/index.xml" rel="self" type="application/rss+xml"/><item><title>四层特权，四条链，一个目标 - ARM TrustZone EL0→EL3 攻击实录</title><link>https://overkazaf.github.io/blogs/posts/arm-trustzone-el0-to-el3-attack-chain-anatomy/</link><pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate><guid>https://overkazaf.github.io/blogs/posts/arm-trustzone-el0-to-el3-attack-chain-anatomy/</guid><description>以 Quarkslab/Project Zero/360 Alpha Lab 的四条真实攻击链为案例，从 ARM 异常等级架构出发，逐层解剖 EL0→S-EL0→S-EL1→EL3 的提权技术：共享内存机制、SMC 调用约定、Trustlet 漏洞模式、TEE 内核提权、Secure Monitor 劫持，以及 Boot Chain 替代路径</description></item></channel></rss>