Back to blog
Cybersecurity

CVE-2026-46242 Bad Epoll: Linux 6.4 Privilege Escalation via Chrome and Android

CVE-2026-46242 Bad Epoll: Linux 6.4-6.9 kernel race condition lets attackers escalate to root from Chrome or Android. Practical guide for Spanish SMBs.

Blurtek
7 min read68 palabras
01

What Is CVE-2026-46242 Bad Epoll?

CVE-2026-46242, dubbed Bad Epoll, is a local privilege escalation (LPE) vulnerability in the Linux kernel epoll subsystem affecting versions 6.4 through 6.9.x. A race condition in ep_remove_safe_wake_up() leaves a dangling pointer exploitable via heap spray to overwrite process credentials and escalate to root. Chrome renderer processes and Android apps can trigger this with minimal permissions, making a previously local vulnerability effectively remotely reachable via a V8 exploit chain.

02

The Chrome and Android Attack Chain

03

Action Plan: What to Do This Week

Does your company have uninventoried Linux servers or Android devices without a patch policy? We run a no-commitment attack surface audit.

Solicitar diagnóstico