Impact
The vulnerability resides in the ARM SMMU driver (arm-smmu-v3.c) in the Android kernel. A logic error in multiple functions allows a local process that can execute arbitrary code to elevate its privileges to system execution level. The flaw does not require any user interaction; it simply relies on the existence of the code‑execution privilege. The CVSS score of 6.7 indicates a moderate severity risk, while the EPSS score of less than 1% reflects a low probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog.
Affected Systems
The affect is part of the ARM SMMU driver bundled with the Android operating system. Devices that received the 2026‑09‑01 security bulletin from Google contain the vulnerable kernel modules. The advisory does not enumerate specific device models or version numbers, so any Android device with the unpatched ARM SMMU driver should be considered at risk.
Risk and Exploitability
Because the flaw is local only, the attacker must already have the ability to run code on the device, such as through a malicious application or another kernel exploit. Once local code execution is achieved, the attacker can trigger the logic error and gain system privileges, granting unrestricted access to all device resources and the ability to install further malware or change device settings. The low EPSS score and lack of KEV listing suggest that, to date, this vulnerability has not been actively exploited in the wild. Nevertheless, the potential impact of escalated system-level control warrants prompt patching.
OpenCVE Enrichment