Gaping 'hole' in Qualcomm’s Secure World mobile vault leaked sensitive data
zdnet.com
zdnet.com
So fundamentally it's a parsing exploit on untrusted user input. They should have been able to simplify and test this mechanism extensively enough to not have this type of vulnerability, because it doesn't sound like researchers even had to go to the level of the timing attacks that came up recently in a related area [0] [1].
[0] http://tpm.fail/ [1] https://news.ycombinator.com/item?id=21520074