What Is CVE-2026-46242 Bad Epoll?
CVE-2026-46242, dubbed Bad Epoll, is a local privilege escalation (LPE) vulnerability in the Linux kernel epoll subsystem affecting versions 6.4 through 6.9.x. A race condition in ep_remove_safe_wake_up() leaves a dangling pointer exploitable via heap spray to overwrite process credentials and escalate to root. Chrome renderer processes and Android apps can trigger this with minimal permissions, making a previously local vulnerability effectively remotely reachable via a V8 exploit chain.
The Chrome and Android Attack Chain
Action Plan: What to Do This Week
Does your company have uninventoried Linux servers or Android devices without a patch policy? We run a no-commitment attack surface audit.
Solicitar diagnóstico