A vulnerability was found in OP-TEE OS up to 4.10.0. It has been declared as critical. Affected is the function
is_user_ta_ctx of the component Widevine PTA. Such manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2026-71967. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.