Researchers disclosed the ITScape vulnerability (CVE-2026-46316) in August 2026, revealing a critical guest-to-host escape bug in KVM on arm64 systems that allows a guest virtual machine to execute commands on the host with kernel-level privileges [1]. Unlike prior QEMU escapes that operate in user space, ITScape's flaw exists inside the in-kernel KVM module, increasing its potential impact by granting root access on the host kernel itself [1].

The vulnerability takes advantage of a race condition in the vGIC-ITS emulation component of KVM on the arm64 architecture, allowing the exploit chain to elevate guest VM privileges beyond their normal isolation boundaries [1]. This is the first publicly documented guest-to-host escape exploit targeting KVM/arm64 environments, marking a significant milestone in vulnerability research for this virtualization platform [1].

The proof-of-concept code demonstrates a full attack chain within the Linux kernel KVM selftest framework, but it is not yet a weaponized exploit that attackers have widely used in real-world scenarios [1]. Nonetheless, this vulnerability poses a serious risk for multi-tenant public cloud providers running arm64 hardware that accept untrusted guest virtual machines, as it could enable privilege escalation to the underlying host operating system [1].

The disclosure and associated patches were initially embargoed to allow affected parties time to prepare fixes. The embargo ended in August 2026, enabling public release of the technical details and security updates [1]. Cloud operators and users of KVM on arm64 systems are urged to update promptly to protect against this elevation-of-privilege flaw. Continued vigilance is expected as the patch rolls out in production environments.