Arm Limited's vulnerability footprint centers on processor intellectual property and supporting software, particularly GPU kernel drivers spanning multiple architectural generations (Midgard, Bifrost, Valhall) and the widely embedded mbed TLS cryptographic library. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the memory-safety and privilege-boundary demands of kernel-level graphics and cryptographic code. The exposure recurs through weakness classes including use-after-free conditions, out-of-bounds reads and writes, and observable discrepancies, which are characteristic of low-level firmware and driver development. Defenders should prioritize GPU driver updates across mobile and embedded deployments, particularly when devices have extended lifecycle requirements, and treat mbed TLS library updates as supply-chain relevant for any downstream products that link it. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arm Limited over time
Of all the CVEs published by Arm Limited as a CNA, 94.2% affect products that Arm Limited develops as a vendor.
Of all the CVEs published that affect products developed by Arm Limited, 29.9% are self-published by Arm Limited as a CNA.
Signals from CVEs in this vendor scope (164 CVEs).
164 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2022-38181HIGH The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Va | Oct 25, 2022 | 8.8 | 74 | YES | NO |
CVE-2017-5715MEDIUM Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access v | Jan 4, 2018 | 5.6 | 74 | NO | YES |
CVE-2017-5754MEDIUM Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access v | Jan 4, 2018 | 5.6 | 71 | NO | NO |
CVE-2021-28663HIGH The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost | May 10, 2021 | 8.8 | 70 | YES | NO |
CVE-2021-28664HIGH The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. | May 10, 2021 | 8.8 | 68 | YES | NO |
CVE-2021-29256HIGH . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost | May 24, 2021 | 8.8 | 67 | YES | NO |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
CVE-2022-22706HIGH Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and | Mar 3, 2022 | 7.8 | 64 | YES | NO |
CVE-2024-4610HIGH Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing opera | Jun 7, 2024 | 7.8 | 63 | YES | NO |
Signals from CVEs in this vendor scope (164 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arm Limited.
Media articles that mention a CVE ID that affects a product developed by Arm Limited — matched by CVE ID, not by vendor name.