CVE-2026-15418: Silicon Labs Silabser.sys Driver

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.

Affected products

  • Silicon Labs Silabser.sys Driver: up to and including 11.5.0

Published 2026-09-10. Last modified 2026-09-10.