Google Project Zero reported that the first handset with ARM Memory Tagging Extension (MTE) reached the market, marking a notable deployment of hardware-backed memory-safety defenses aimed at detecting classes of memory corruption such as use-after-free and out-of-bounds access. The rollout followed Project Zero's earlier implementation testing of MTE, which examined how the feature behaves in practice and highlighted its potential to harden user-space software against exploitation techniques long used in browser and sandbox escapes.
Subsequent analysis of MTE in major heap allocators found that the protection materially improves heap-corruption mitigation but leaves important differences in coverage and bypass resistance. Research comparing Chrome's PartitionAlloc, glibc ptmalloc, and Android's Scudo said allocator design choices affect tag randomization, chunk-size coverage, and performance, and noted a previously reported weakness in PartitionAlloc's deterministic tag increment and tag reuse that could let a use-after-free attacker cycle tags to evade checks under some conditions. The findings also said MTE does not fully solve uninitialized memory, stack safety, large shared-buffer protection, or all mmap-backed allocation cases, underscoring that the new handset support is a meaningful but incomplete step in reducing memory-corruption risk.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
The Google Pixel 8 was identified as the first smartphone released in 2023 to support ARM MTE. This represented the first handset availability of the mitigation discussed in the references.
ARM introduced Memory Tagging Extensions (MTE) as part of the ARMv8.5-A architecture. This established the hardware capability later used by allocators and devices to detect some memory-safety errors.
DarkNavy published an analysis comparing MTE behavior in Chrome's PartitionAlloc, Glibc's Ptmalloc, and Android's Scudo. The article concluded that MTE materially improves heap-corruption mitigation but leaves important gaps and allocator-specific trade-offs.
Researchers reported issues in Chrome PartitionAlloc's MTE implementation to Google, including deterministic tag increment on free and likely tag reuse on allocation that could enable a use-after-free bypass. The Chrome team confirmed the issue, and the article cites Chrome Issue 1512538 for a fuller report and proof of concept.
Google Project Zero published "MTE As Implemented, Part 1: Implementation Testing," analyzing how MTE was implemented and tested in practice. This marked a public technical examination of allocator-level MTE behavior.
Google Project Zero published "Virtually Unlimited Memory: Escaping the Chrome Sandbox," documenting a Chrome sandbox escape based on memory corruption. The reference provides historical context for later MTE-focused mitigation work.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
darknavy.org
Open sourcedarknavy.org
Open sourcegoogleprojectzero.blogspot.com
Open sourcegoogleprojectzero.blogspot.com
Open sourcegoogleprojectzero.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.