Permission Bypass in ARM SMMU Drivers Affecting Android Devices
CVE-2026-58747

6.7MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-58747?

The vulnerability in the ARM SMMU driver involves a logic error in the smmu_detach_dev function, which enables a potential permission bypass. This flaw allows for local escalation of privileges without requiring user interaction. Exploitation of this vulnerability could grant an attacker access to system execution privileges, posing a significant security risk to devices relying on this driver. It is essential for affected users to stay informed and apply necessary updates to mitigate potential threats.

Affected Version(s)

Android Android kernel

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.