A critical race condition vulnerability, CVE-2025-38352, affecting the Linux kernel's POSIX CPU timers implementation has been publicly disclosed, with a proof-of-concept (PoC) exploit named 'Chronomaly' released on GitHub. The vulnerability is a use-after-free flaw in the handle_posix_cpu_timers() function, primarily impacting 32-bit Android devices where the CONFIG_POSIX_CPU_TIMERS_TASK_WORK flag is disabled. Exploitation allows attackers to achieve privilege escalation or execute arbitrary code in the kernel, and the exploit does not require kernel symbol offsets, making it highly portable across different configurations. The exploit leverages advanced race-window extension and cross-cache allocation techniques, requiring a multi-core system for reliable exploitation, and has been successfully demonstrated on QEMU-virtualized Linux kernels running v5.10.157.
The vulnerability has been added to CISA’s Known Exploited Vulnerabilities Catalog, indicating active exploitation in the wild. Security researchers have provided detailed technical analysis and exploitation steps, highlighting the risk to unpatched systems, especially those running vulnerable 32-bit Android kernels. Organizations are urged to review their Linux kernel configurations and apply patches or mitigations to prevent potential privilege escalation attacks stemming from this flaw.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2025-38352 to its Known Exploited Vulnerabilities Catalog, reflecting confirmed exploitation and elevating the urgency of remediation. This formalized the vulnerability's status as an actively exploited security issue.
An upstream fix was released to address CVE-2025-38352 in the Linux kernel. Administrators and device makers were advised to update to patched kernels or enable CONFIG_POSIX_CPU_TIMERS_TASK_WORK as a mitigation.
Reports said CVE-2025-38352 was being actively exploited, primarily against 32-bit Android devices, and that the Chronomaly exploit could grant root access on vulnerable Linux kernels. The issue was also noted as potentially affecting other 32-bit Linux-based systems.
Security researcher Faith from Zellic released a working exploit named Chronomaly for CVE-2025-38352. The exploit was described as portable across kernel configurations because it does not require kernel symbol offsets or fixed memory addresses.
A critical use-after-free vulnerability in the Linux kernel's POSIX CPU timers implementation, tracked as CVE-2025-38352, was publicly disclosed. The flaw affects systems where CONFIG_POSIX_CPU_TIMERS_TASK_WORK is disabled and can enable privilege escalation or kernel code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.