Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
HackerOne Mandates ID Verification for Bug Bounty Submissions
August 1, 2026
Arch Linux Disables AUR Package Takeovers After Malicious Commits
August 1, 2026
Keycloak CVE-2024-3700 Exposes User Data Across Admin Boundaries
July 31, 2026
Home/CyberSecurity News/PoC Exploit Released for Android/Linux Kernel Vulnerability CVE-2025-38352
CyberSecurity News

PoC Exploit Released for Android/Linux Kernel Vulnerability CVE-2025-38352

Exploiting a critical race condition vulnerability in the Linux kernel (CVE-2025-38352) is now possible with the public release of a proof-of-concept (PoC Exploit Targets the POSIX CPU timers...

Jennifer sherman
Jennifer sherman
January 7, 2026 2 Min Read
109 0

Exploiting a critical race condition vulnerability in the Linux kernel (CVE-2025-38352) is now possible with the public release of a proof-of-concept (PoC Exploit Targets the POSIX CPU timers implementation and was previously exploited in limited, targeted attacks against 32-bit Android devices.

CVE-2025-38352 is a use-after-free (UAF) vulnerability in the Linux kernel’s handle_posix_cpu_timers() function.

The flaw occurs when the CONFIG_POSIX_CPU_TIMERS_TASK_WORK configuration flag is disabled, a setting found on most 32-bit Android kernels but not on 64-bit systems.

The vulnerability arises from a race condition that occurs when POSIX CPU timers fire on zombie tasks.

By carefully timing the creation of a zombie process, reaping it through a parent process, and triggering timer deletion, attackers can cause the kernel to access freed memory, leading to privilege escalation or kernel code execution.

Chronomaly Exploit

Security researcher Faith (working at blockchain security firm Zellic) has released “Chronomaly,” a fully functional exploit targeting Linux kernel versions v5.10.x.

The exploit was introduced through a comprehensive three-part technical blog series covering the vulnerability’s discovery, analysis, and exploitation techniques.

Chronomaly
Chronomaly

The exploit is notable for not requiring kernel symbol offsets or specific memory addresses, making it portable across different kernel configurations.

It implements sophisticated race-window extension techniques via CPU timer manipulation and a cross-cache allocation strategy for sigqueue structures.

The exploit requires a multi-core system with at least two CPUs to reliably trigger the race condition.

Testing confirms successful exploitation on QEMU-virtualized Linux kernels running v5.10.157, with parameters adjustable for different environments.

The vulnerability has been added to CISA’s Known Exploited Vulnerabilities Catalog, indicating active exploitation.

While the threat primarily affects 32-bit Android devices, the kernel components involved are also present in 32-bit variants of other Linux-based systems.

According to the GitHub advisory, users should update to a patched kernel or enable the CONFIG_POSIX_CPU_TIMERS_TASK_WORK option.

The upstream Linux kernel patch (commit f90fff1e152dedf52b932240ebbd670d83330eca) addresses the vulnerability by preventing timer processing on zombie tasks.

Device manufacturers and system administrators should prioritize kernel updates to mitigate this critical vulnerability.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

From Tycoon2FA to Lazarus Group – Inside ANY.RUN’s Biggest Discoveries of 2025

Next Post

Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
FBI Warns North Korean IT Workers Exploit Stolen Identities
July 31, 2026
Google AI Agents Find and Fix 1,072 Chrome Vulnerabilities
July 31, 2026
North Korean EtherHiding Targets Crypto Wallets and Developer Credentials
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us