A vulnerability was found in OP-TEE OS up to 4.10.0. It has been declared as critical. Affected is the function is_user_ta_ctx of the component Widevine PTA. Such manipulation leads to null pointer dereference.

This vulnerability is listed as CVE-2026-71967. The attack may be performed from remote. There is no available exploit.

Applying a patch is advised to resolve this issue.