Coverage › CVE-2022-38181
CVE-2022-38181 Mapped Mobile only
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
- Vendor / product
- Arm — Mali Graphics Processing Unit (GPU)
- Description (CISA)
- Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
- Added to KEV
- 2023-03-30
- Due date
- 2023-04-20
- Required action
- Apply updates per vendor instructions.
- Known ransomware use
- Unknown
- CWE
- CWE-416
- CISA notes
- https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
https://nvd.nist.gov/vuln/detail/CVE-2022-38181 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1660 Phishingmobile | exploitation technique | This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload. ref 1 · ref 2 · ref 3 · ref 4 · ref 5 |
not checked (Mobile) |
| T1404 Exploitation for Privilege Escalationmobile | primary impact | This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload. ref 1 · ref 2 · ref 3 · ref 4 · ref 5 |
not checked (Mobile) |
| T1437.001 Web Protocolsmobile | primary impact | This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload. ref 1 · ref 2 · ref 3 · ref 4 · ref 5 |
not checked (Mobile) |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
No live Enterprise technique to traverse.