CVE-2023-26083
Arm Mali GPU Kernel Driver Information Disclosure Vulnerability
- Published
- Apr 6, 2023
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Apr 7, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NLow · next 30 days
- Percentile
- 66.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.
Sources
2CVE-2023-26083-Mali-InfoLeak-PoC
- Pixel_GPU_ExploitExploit
Android 14 kernel exploit for Pixel7/8 Pro
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.