kevmap

Coverage › CVE-2022-38181

CVE-2022-38181 Mapped Mobile only

Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Vendor / product
Arm — Mali Graphics Processing Unit (GPU)
Description (CISA)
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
Added to KEV
2023-03-30
Due date
2023-04-20
Required action
Apply updates per vendor instructions.
Known ransomware use
Unknown
CWE
CWE-416
CISA notes
https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
https://nvd.nist.gov/vuln/detail/CVE-2022-38181
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.

TechniqueMapping typeCTID commentStatus in v19.2
T1660 Phishingmobile exploitation technique This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload.
ref 1 · ref 2 · ref 3 · ref 4 · ref 5
not checked (Mobile)
T1404 Exploitation for Privilege Escalationmobile primary impact This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload.
ref 1 · ref 2 · ref 3 · ref 4 · ref 5
not checked (Mobile)
T1437.001 Web Protocolsmobile primary impact This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload.
ref 1 · ref 2 · ref 3 · ref 4 · ref 5
not checked (Mobile)

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

No live Enterprise technique to traverse.