Junglewise Threat Intelligence

CVE-2026-22165: Imagination Technologies GPU DDK use after free in GLES render process

CVE-2026-22165 · Severity: high · CVSS 8.1 · Published 2026-05-01

Technologies: Imagination Technologies GPU DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in Imagination Technologies GPU drivers could allow a malicious web page to crash the graphics rendering process. In certain configurations where the graphics process has high system privileges, this could be used as a stepping stone for further attacks or to compromise the device. This affects devices using specific GPU hardware and software drivers commonly found in mobile and embedded systems.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU GLES user-space shared library of the Imagination Technologies GPU DDK. The flaw is triggered when the GPU GLES render process processes 'unusual' WebGPU content from a web page. This results in a write UAF condition. While the primary impact is a process crash, on platforms where the graphics workload process executes with elevated system privileges, an attacker could potentially leverage this for arbitrary code execution or further device compromise. The vulnerability is addressed in DDK versions following 25.2 RTM.

Affected products

  • Imagination Technologies GPU DDK up to and including 25.2 RTM

Timeline

  • 2026-05-01: disclosed: Initial NVD publication
  • 2026-05-01: advisory: Imagination Technologies vendor advisory updated

References

Related threats