Executive brief
A security vulnerability exists in several Arm processor families, including Neoverse and Cortex-X/A series, which are widely used in servers, mobile devices, and automotive systems. This flaw could allow a lower-privileged program to modify data or resources that should be protected by the operating system or secure firmware. If exploited, this could lead to a compromise of the system's integrity or an escalation of privileges, potentially allowing an attacker to bypass security boundaries.
Technical details
A race condition (CWE-362) exists in multiple Arm CPU architectures, including Neoverse and various Cortex cores. The vulnerability allows an attacker at a lower Exception Level (EL) to perform unauthorized writes to resources that are technically owned by a higher Exception Level. This suggests a failure in hardware-level synchronization or access control enforcement during concurrent execution. An attacker with local execution capabilities could potentially leverage this to escalate privileges or corrupt sensitive system state. Affected models span high-performance server cores (Neoverse) and mobile/consumer cores (Cortex-X and Cortex-A series).
Affected products
- Arm C1-Ultra
- Arm C1-Premium
- Arm Neoverse V3 & V3AE
- Arm Neoverse V2
- Arm Neoverse V1
- Arm Neoverse-N2
- Arm Neoverse-N1
- Arm Cortex-X925
- Arm Cortex-X4
- Arm Cortex-X3
- Arm Cortex-X2
- Arm Cortex-X1 & X1C
- Arm Cortex-A710
- Arm Cortex-A78, A78AE & A78C
- Arm Cortex-A77
- Arm Cortex-A76 & A76A
Timeline
- 2026-06-09: disclosed: Initial disclosure by Arm Limited
- 2026-06-09: advisory: NVD record published