Exploiting QSEE Vulnerabilities In Google's Wifi Pro
Cristofaro Mune
OffensiveCon 2026 · Day 1 · Main Stage
This talk, "Exploiting QSEE Vulnerabilities In Google's Wifi Pro," delivered by Cristofaro Mune of Raelize, delves into critical security vulnerabilities discovered within the **Qualcomm QSEE (Qualcomm Secure Execution Environment)** implementation on the Google Nest Wi-Fi Pro router. Mune, presenting research conducted in collaboration with Nick Teemus, details a comprehensive methodology for achieving **EL3 (Exception Level 3)** code execution – the highest privilege level on an ARM-based System-on-Chip (SoC) – on a widely deployed consumer device.
AI review
Mune and Teemus deliver a complete, hardware-grounded EL3 exploitation chain against a shipping consumer device — 12 high/critical CVEs, novel XPU register manipulation as a exploitation primitive, and live demos that hold up. This is the kind of work that redefines how practitioners think about TEE attack surface.