Some top ARM GPUs have a potentially worrying security flaw – here’s what you need to know
Chip manufacturing powerhouse ARM has published a security advisory claiming to have addressed a high-severity vulnerability affecting its popular Mali GPU drivers.
The vulnerability, tracked as CVE-2023-4211, is allegedly being used in “limited, targeted exploitation” attacks, the company added, as an improper access to freed memory, but could also be used to compromise, or manipulate, sensitive data.
Among possibly vulnerable devices, BleepingComputer also states, are the Samsung Galaxy S20/S20 FE, Xiaomi Redmi K30/K40, Motorola Edge 40, and OnePlus Nord 2.
Affected driver versions include Midgard GPU kernel driver (all versions from r12p0 to r32p0), Bifrost GPU kernel driver (all versions from r0p0 to r42p0), Valhall GPU kernel driver (all versions from r19p0 to r42p0), and Arm 5th Gen GPU architecture kernel driver (all versions from r41p0 to r42p0).
ARM said it fixed the problem for the Bifrost, Valhall, and Arm 5th Gen GPU architecture in the kernel driver version r43p0, so if you’re worried about being compromised, make sure to bring your endpoints up to date. Midgard, being an older model, is no longer supported, and thus will not be getting a patch.
While ARM did say that the vulnerability was being used in the wild in “limited, targeted exploitation”, it did not elaborate further. However, we do know that the flaw was discovered by Google’s Threat Analysis Group (TAG), and Project Zero. TAG is known for tracking and analyzing state-sponsored threat actors, which are also known to engage in targeted attacks, rather than casting a wide net.
Elsewhere in the advisory, ARM detailed a pair of other vulnerabilities – CVE-2023-33200 and CVE-2023-34970, which affect Bifrost, Valhall, and Arm’s 5th Gen GPU architecture kernel driver versions up to r44p0. The company recommends users install upgrades r44p1 and r45p0.
Via BleepingComputer
More from TechRadar Pro
Chip manufacturing powerhouse ARM has published a security advisory claiming to have addressed a high-severity vulnerability affecting its popular Mali GPU drivers. The vulnerability, tracked as CVE-2023-4211, is allegedly being used in “limited, targeted exploitation” attacks, the company added, as an improper access to freed memory, but could also be…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
- WiiM expands its whole-home ecosystem with a new soundbar
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023