Skip to content
CVSS 9.1 · CRITICAL

CVE-2025-10263

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

View on NVD

Analysis

A critical vulnerability has been identified in several Arm processor cores, including Neoverse (widely used in AWS Graviton and other cloud instances) and Cortex-A/X series. The flaw allows an attacker to write to resources owned by a higher exception level, potentially bypassing the security boundaries between applications, the operating system, and the hypervisor.

Relevant roles

HardwareCloudLinuxCyberSecurityBackendDocker

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-362CWE-266

EPSS

Probability of exploitation (next 30 days): 0.0053 (0.5%)
Percentile: 41.1%
EPSS: 2026-07-14

Technical description

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

Published: 6/9/2026, 10:16:33 AM
Last modified: 7/15/2026, 2:17:10 AM

References

HomeEventsBlogResourcesCoursesTeam