{"cveID":"CVE-2022-38181","vendorProject":"Arm","product":"Mali Graphics Processing Unit (GPU)","vulnerabilityName":"Arm Mali GPU Kernel Driver Use-After-Free Vulnerability","dateAdded":"2023-03-30","shortDescription":"Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-04-20","knownRansomwareCampaignUse":"Unknown","notes":"https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities;  https://nvd.nist.gov/vuln/detail/CVE-2022-38181","cwes":["CWE-416"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"mobile","cve":"CVE-2022-38181","technique":"T1660","technique_name_at_mapping":"Phishing","mapping_type":"exploitation_technique","capability_group":"use_after_free","comments":"This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload. ","references":["https://thehackernews.com/2023/03/spyware-vendors-caught-exploiting-zero.html","https://www.tomsguide.com/news/android-system-flaws-can-be-remotely-exploited-by-hackers-install-the-latest-updates-now","https://www.techradar.com/pro/security/android-has-a-worrying-security-flaw-so-users-need-to-update-now","https://therecord.media/spyware-google-italy-malaysia-kazakhstan-uae","https://therecord.media/google-zero-days-report-2022"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2022-38181","technique":"T1404","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload. ","references":["https://thehackernews.com/2023/03/spyware-vendors-caught-exploiting-zero.html","https://www.tomsguide.com/news/android-system-flaws-can-be-remotely-exploited-by-hackers-install-the-latest-updates-now","https://www.techradar.com/pro/security/android-has-a-worrying-security-flaw-so-users-need-to-update-now","https://therecord.media/spyware-google-italy-malaysia-kazakhstan-uae","https://therecord.media/google-zero-days-report-2022"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2022-38181","technique":"T1437.001","technique_name_at_mapping":"Web Protocols","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This vulnerability was exploited in a targeted spyware campaign against individuals in Italy, Malaysia, and Kazakhstan. Threat actors used this vulnerability, along with other CVEs, to escalate privileges on Android devices via malicious apps. The campaign involved sending SMS messages with shortened links that redirected users to exploit-hosting web pages. Android users who accessed these links through the Samsung Internet Browser were redirected to Chrome using intent redirection to deliver an unspecified payload. ","references":["https://thehackernews.com/2023/03/spyware-vendors-caught-exploiting-zero.html","https://www.tomsguide.com/news/android-system-flaws-can-be-remotely-exploited-by-hackers-install-the-latest-updates-now","https://www.techradar.com/pro/security/android-has-a-worrying-security-flaw-so-users-need-to-update-now","https://therecord.media/spyware-google-italy-malaysia-kazakhstan-uae","https://therecord.media/google-zero-days-report-2022"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1404","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":false},{"id":"T1437.001","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Web Protocols","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":false},{"id":"T1660","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Phishing","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":0,"has_detection_strategy":false}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["mobile"],"sigma_coverage":"n/a","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}