Android Kernel Privilege Escalation Vulnerability in KVM Component

Vulnerability

A privilege escalation vulnerability has been identified in the Android kernel, specifically within the KVM component for ARM64 architecture. This vulnerability arises from a logic error in the 'hyp-main.c' file, which can lead to local information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does not involve user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing a user to gain elevated rights or access within the system.

Remediation

Users can update their devices to the March 2025 security patch level to address this vulnerability.

Added: Aug 26, 2025, 11:21 PM
Updated: Aug 26, 2025, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.3
remediation
0.0
relevance
0.4
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.