Kernelsu is a privilege-escalation and kernel-module framework for Android that extends device capabilities through kernel-level access, presenting a narrow but high-sensitivity attack surface. The recurring vulnerability classes affecting the project center on authentication and authorization mechanisms, including incorrect authorization checks and authentication-bypass vulnerabilities that could undermine the trust boundaries the framework is designed to enforce. Current vulnerability counts and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kernelsu over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5521CRITICAL Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9. | Oct 11, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-49794HIGH KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in KernelSU kernel module can be bypassed, which causes any mal | Jan 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-46139MEDIUM KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelSU installed device is infected with a malware whose app sign | Oct 31, 2023 | 5.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kernelsu.
Media articles that mention a CVE ID that affects a product developed by Kernelsu — matched by CVE ID, not by vendor name.