logo

Mind the Gap

ID: 18bab96b-1dee-5e7a-8906-a891d759fa8e

STIX ID: report--18bab96b-1dee-5e7a-8906-a891d759fa8e

Feed Name: Google Project Zero

Threat Score
85/100

Date Published: 2022-11-22

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Project Zero researchers discovered and reported five vulnerabilities in the ARM Mali GPU kernel driver that can disclose physical addresses, cause physical-page use-after-free, and corrupt kernel memory—issues that can be chained to escalate privileges and fully compromise Android devices using Mali GPUs. ARM published patches (CVE-2022-36449) in July–August 2022, but Project Zero found that downstream vendors had not rolled the fixes out to affected devices, creating a significant patch gap and continued exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.