December 1, 2023

Arm is warning its that Mali GPU driver has a vulnerability that’s being actively exploited by dangerous actors.

Arm revealed the exploit in an advisory:

An area non-privileged person could make improper GPU processing operations to use a software program race situation. If the system’s reminiscence is fastidiously ready by the person, then this in flip may give them entry to already freed reminiscence.

The corporate says the answer is to improve the motive force to a more recent model:

This challenge is mounted in Bifrost, Valhall and Arm fifth Gen GPU Structure Kernel Driver r44p1 and r45p0. Customers are really useful to improve if they’re impacted by this challenge.

Based on Ars Technica, Google’s Pixel line of smartphones — particularly the Pixel 7 — are among the many most high-profile gadgets weak to this exploit. Happily, Google addressed the problem in its September replace.