Impact
The vulnerability arises from a logic error in the arm-smmu-v3.c driver, creating a use‑after‑free condition. Exploitation of this flaw can grant a local attacker elevated privileges, allowing the execution of system‑level code. The weakness is a classic use‑after‑free flaw (CWE‑416). There is no requirement for user interaction; once the device is compromised, the attacker can leverage the flaw to gain higher authority.
Affected Systems
The flaw is present in Google's Android operating system on devicesv3 driver. Specific Android releases prior to the security bulletin dated 2026‑09‑01 are affected. Precise version numbers are not listed in the advisory, so all installations of Android using that driver before the update are at risk.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate impact, and the vulnerability is not listed in CISA’s KEV a malicious application or privileged user could trigger the use‑after‑free, leading to privilege escalation without additional user interaction. The exploit requires the attacker to have some local presence on the device.
OpenCVE Enrichment