CVE-2021-28663 is a use-after-free vulnerability in the Arm Mali GPU kernel driver caused by mishandled GPU memory operations. A non-privileged local user can perform improper GPU-memory operations that trigger a use-after-free condition. Affected driver releases include Bifrost r0p0 through r28p0, Valhall r19p0 through r28p0, and Midgard r4p0 through r30p0 before r29p0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real local Android kernel privilege-escalation project centered on Arm Mali GPU driver vulnerabilities, primarily CVE-2022-38181, adapted for an Amazon Fire HD 10 (KFTRWI/trona) running Fire OS 7.3.2.6 on MT8183 with Mali-G72/kbase r14p0. It is not a framework module; it is a standalone research/exploit repo with documentation, PoCs, diagnostics, and automation scripts. Repository structure: top-level markdown files (README.md, HANDOFF.md, REVIEW.md, STATE.md, blog.md) document the research history, exploit design, review findings, and final chain. The poc-28663/ directory contains the actual C code: low-level headers (mali.h, mali_trona.h), older leak PoCs (mali_poc.c, mali_poc_trona.c), validation tools (gpu_test.c, alias_write_test.c, dump_probe.c, diag*.c), staged exploit-development programs (jit_trigger.c, stageb*.c, stagec.c, diagd.c), and the main exploit (exploit_trona.c). Bash scripts (grind.sh, grind2.sh, root_grind.sh) automate repeated deployment and reboot-loop grinding over ADB. Main exploit capability: exploit_trona.c implements a full local root chain. It opens /dev/mali0, initializes a Mali context, triggers the CVE-2022-38181 JIT allocator use-after-free by marking a JIT region DONT_NEED and forcing shrinker reclamation, sprays replacement regions, aliases them, and uses GPU WRITE_VALUE jobs to corrupt GPU page-table entries. The documented final chain then derives arbitrary physical read/write, locates kernel anchors such as init_task, init_cred, modprobe_path, and selinux_enforcing, disables SELinux, overwrites credentials/capabilities, and abuses modprobe_path to execute a helper script from /data/local/tmp as root. Supporting code confirms each primitive independently: jit_trigger.c proves the JIT region can be reclaimed while still referenced; stageb/stagec/diagd validate replacement and freeing behavior; gpu_test.c validates GPU command submission; alias_write_test.c proves GPU writes through a PROT_NONE alias affect shared backing; dump_probe.c parses GPU MMU dumps; diag/diag2 investigate driver quirks and memory-pool behavior. The bash grinders repeatedly push the exploit to /data/local/tmp/exploit_trona via adb, execute it, monitor logs, and reboot on crashes/timeouts. Attack surface and targeting are strictly local: the exploit requires code execution on the device and access to the Mali device node. There are no remote C2 or network callbacks in the exploit code. The most fingerprintable artifacts are local device files (/dev/mali0, /dev/binder, /dev/kmsg, /sys/fs/selinux/enforce), on-device payload paths under /data/local/tmp, and hardcoded physical/kernel addresses specific to the targeted firmware build. Overall, this is an operational exploit-development repository for a device-specific Android local root chain, with substantial engineering notes and multiple intermediate PoCs rather than a single minimal exploit.
This repository is a proof-of-concept (PoC) exploit for CVE-2021-28663, a design flaw in the ARM Mali GPU Android kernel driver. The repository contains four files: a README.md with usage instructions and background, a shell script (compile.sh) for compiling the PoC on ARM64 Android using the NDK, a header file (mali.h) defining necessary ioctl structures and constants, and the main exploit code (mali_poc.c). The exploit works by opening /dev/mali0, performing a series of ioctls and memory mappings to manipulate GPU virtual addresses and memory flags, and ultimately leaking kernel memory addresses to userland. The leaked data is written to 'dump.bin' for further analysis. The exploit demonstrates the vulnerability by searching for kernel addresses in the mapped memory and reporting them. The attack vector is local, requiring code execution on a vulnerable Android device with the Mali GPU driver. No remote or network endpoints are involved. The code is a functional PoC and does not provide privilege escalation or arbitrary code execution, but demonstrates kernel memory disclosure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Arm Mali GPU Kernel Driver vulnerability involving improper operations on GPU memory that can trigger a use-after-free scenario and may enable root privilege escalation or information disclosure.
A use-after-free vulnerability in Arm's Mali GPU referenced as a previously patched Android-related zero-day.
An Arm Mali GPU Kernel Driver vulnerability that allows improper operations on GPU memory, potentially causing a use-after-free condition, privilege escalation to root, and information disclosure.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.