ZeroHour

CVE-2026-9034

mass

Use-After-Free in Arm Bifrost, Valhall, and 5th Gen GPU Userspace Drivers

CVSS 3.1
7.8 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-9034 is a use-after-free (CWE-416) in the Arm Bifrost, Valhall, and Arm 5th Gen GPU Architecture userspace drivers, the driver software shipped for Arm Mali-architecture GPUs. A non-privileged local process can trigger the flaw simply by performing valid GPU processing operations, including WebGL or WebGPU workloads from web content, causing the driver to access already-freed memory. Depending on conditions this can lead to information disclosure, memory corruption, or crashes, reflected in the CVSS 3.1 score of 7.8 (high) with high impact to confidentiality, integrity, and availability, a local attack vector, low privileges required, and no user interaction. Any system shipping the affected driver releases is exposed, most plausibly Android phones and tablets, Chromebooks, and other Arm SoC-based devices using these Mali GPU generations, with the actual population depending on the driver versions individual vendors shipped. There is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns roughly a 0.1% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Patch the GPU userspace driver to a release outside the affected ranges (for Bifrost, later than r51p0 or r54p3 depending on branch; for Valhall and Arm 5th Gen, later than r55p0), which on Android and Chrome OS typically arrives through device/OS vendor security updates and on Linux through the vendor's driver distribution. Inventory affected endpoints by checking Arm Mali driver version strings and vendor security bulletins, prioritizing systems that run untrusted web content since WebGL/WebGPU workloads can trigger the flaw; no workarounds are documented.

Affected
Arm Bifrost GPU Userspace Driverr42p0 through r49p5, r50p0 through r51p0, r54p1 through r54p3
Arm Valhall GPU Userspace Driverr42p0 through r49p5, r50p0 through r54p3, r55p0
Arm 5th Gen GPU Architecture Userspace Driverr42p0 through r49p5, r50p0 through r54p3, r55p0
Estimated exposure
masson the order of hundreds of millions of devices (estimated) — Arm Mali GPUs of the affected generations are widely deployed across Android smartphones and tablets, Chromebooks, and other Arm SoC consumer devices, so the plausible affected population is on the scale of the Arm consumer-device install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Bifrost GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p3; Valhall GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.