Junglewise Threat Intelligence

CVE-2026-22166: Imagination Technologies GPU DDK use after free in GLES render process

CVE-2026-22166 · Severity: high · CVSS 8.1 · Published 2026-05-01

Technologies: Imagination Technologies GPU DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability exists in the Imagination Technologies GPU driver software used in various computing devices. By loading a specially crafted web page with unusual graphics content, an attacker could cause the system's graphics processing component to crash or potentially execute unauthorized commands. This could lead to a complete system compromise or service disruption, especially on platforms where graphics processes run with high system privileges.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU GLES user-space shared library of the Imagination Technologies GPU DDK. The flaw is triggered when the GPU GLES render process processes 'unusual' WebGPU content from a web page. An attacker can exploit this memory corruption to cause a write-after-free condition. On platforms where the graphics workload process operates with elevated system privileges, this can be leveraged to achieve further exploitation or arbitrary code execution. The vulnerability affects DDK versions up to and including 25.2 RTM and is addressed in version 25.3 RTM.

Affected products

  • Imagination Technologies GPU DDK up to and including 25.2 RTM

Timeline

  • 2026-05-01: disclosed
  • 2026-05-01: advisory
  • 2026-06-01: patched: NVD record updated with patched version info

References

Related threats