Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
Conclusion & alert: CVE-2017-5927 is rated High Exploit Risk (65.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.38%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.31% | 0.38% | +0.07% |
| 2 | 2025-11-18 | 0.38% | 0.31% | -0.07% |
| 3 | 2025-05-06 | — | 0.38% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
low | — | https://www.suse.com/security/cve/CVE-2017-5927/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| allwinner | a64 | — | cpe:2.3:h:allwinner:a64:-:*:*:*:*:*:*:* |
| amd | athlon_ii_640_x4 | — | cpe:2.3:h:amd:athlon_ii_640_x4:-:*:*:*:*:*:*:* |
| amd | e-350 | — | cpe:2.3:h:amd:e-350:-:*:*:*:*:*:*:* |
| amd | fx-8120_8-core | — | cpe:2.3:h:amd:fx-8120_8-core:-:*:*:*:*:*:*:* |
| amd | fx-8320_8-core | — | cpe:2.3:h:amd:fx-8320_8-core:-:*:*:*:*:*:*:* |
| amd | fx-8350_8-core | — | cpe:2.3:h:amd:fx-8350_8-core:-:*:*:*:*:*:*:* |
| amd | phenom_9550_4-core | — | cpe:2.3:h:amd:phenom_9550_4-core:-:*:*:*:*:*:*:* |
| intel | atom_c2750 | — | cpe:2.3:h:intel:atom_c2750:-:*:*:*:*:*:*:* |
| intel | celeron_n2840 | — | cpe:2.3:h:intel:celeron_n2840:-:*:*:*:*:*:*:* |
| intel | core_i5_m480 | — | cpe:2.3:h:intel:core_i5_m480:-:*:*:*:*:*:*:* |
| intel | core_i7-2620qm | — | cpe:2.3:h:intel:core_i7-2620qm:-:*:*:*:*:*:*:* |
| intel | core_i7-3632qm | — | cpe:2.3:h:intel:core_i7-3632qm:-:*:*:*:*:*:*:* |
| intel | core_i7-4500u | — | cpe:2.3:h:intel:core_i7-4500u:-:*:*:*:*:*:*:* |
| intel | core_i7-6700k | — | cpe:2.3:h:intel:core_i7-6700k:-:*:*:*:*:*:*:* |
| intel | core_i7_920 | — | cpe:2.3:h:intel:core_i7_920:-:*:*:*:*:*:*:* |
| intel | xeon_e3-1240_v5 | — | cpe:2.3:h:intel:xeon_e3-1240_v5:-:*:*:*:*:*:*:* |
| intel | xeon_e5-2658_v2 | — | cpe:2.3:h:intel:xeon_e5-2658_v2:-:*:*:*:*:*:*:* |
| nvidia | tegra_k1_cd570m-a1 | — | cpe:2.3:h:nvidia:tegra_k1_cd570m-a1:-:*:*:*:*:*:*:* |
| nvidia | tegra_k1_cd580m-a1 | — | cpe:2.3:h:nvidia:tegra_k1_cd580m-a1:-:*:*:*:*:*:*:* |
| samsung | exynos_5800 | — | cpe:2.3:h:samsung:exynos_5800:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.cs.vu.nl/~herbertb/download/papers/anc_ndss17.pdf | Exploit Technical Description Third Party Advisory |
| http://www.securityfocus.com/bid/96459 | |
| https://www.vusec.net/projects/anc | Exploit Technical Description Third Party Advisory |