Arm has issued a security bulletin warning of a memory-related flaw in the Bifrost and Valhall GPU core driver programs , which is being actively exploited.
See also: ThinkPHP flaws exploited and installed "Dama" web shells

The security issue is tracked as CVE-2024-4610 and is a UAF vulnerability, affecting all versions of the Bifrost and Valhall drivers from r34p0 to r40p0.
UAF errors occur when a program continues to use a pointer to a memory location after it has been freed. These errors can lead to information disclosure and arbitrary code execution.
“A local unprivileged user can perform improper GPU memory manipulation operations to access already freed memory,” explains about the flaw.
The company also said itis “aware of reports of this vulnerability. Users to upgrade if they are affected by this issue.”
Arm fixed the flaw in version r41p0 of the Bifrost and Valhall GPU Kernel Driver, which was released on November 24, 2022.Currently, the latest version of the drivers is r49p0.
See also: Cisco: Fixed Webex vulnerabilities used for German government surveillance
Due to the complexity of the Android, many end users may receive fixed drivers with significant delays.

Once Arm releases a security update for any flaw, device manufacturers must integrate it into firmware , and in many cases carriers must also approve it. Depending on the phone model, some manufacturers may choose to focus on newer devices and discontinue support for older ones.
Bifrost-based Mali GPUs are used in smartphones/tablets (G31, G51, G52, G71, and G76) , single-board computers , Chromebooks , and various embedded systems.
Valhall GPUs are found in high-end smartphones/tablets with chips like the Mali G57 and G77 , car infotainment systems, and high-performance smart TVs.
It is important to note that some of the affected devices may no longer be supported with security updates.
See also: Cox fixes API auth bypass vulnerability in millions of modems
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A security flaw, also known as a vulnerability, such as Arm’s, is a defect or weakness in a system that an attacker can exploit to compromise its integrity, confidentiality, or availability. These flaws can arise from a variety of issues, such as software bugs, misconfigured systems, or inadequate security policies. When left unaddressed, security flaws can lead to unauthorized access, data breaches, and significant financial and reputational damage. Identifying and mitigating these vulnerabilities through regular security audits, updates, and patching is crucial to maintaining strong cybersecurity defenses.
Source: bleepingcomputer
