Executive brief
A vulnerability in the Imagination Technologies GPU driver could allow a malicious application to access data from other secure processes running on the same graphics processor. This flaw breaks the isolation between secure tasks, potentially leading to the theft of sensitive information or causing the graphics hardware to crash and reset. This could result in data corruption or a temporary loss of service for users of the affected device.
Technical details
An improper isolation or compartmentalization vulnerability (CWE-653) exists in the Imagination Technologies GPU DDK kernel module. The flaw allows shared secure memory allocations to be accessed across different secure GPU processes. A local attacker can exploit this to cooperatively pass data between supposedly isolated secure processes or disrupt the operation of another secure process. Such disruption can lead to image corruption and trigger GPU hardware recovery mechanisms. The vulnerability is addressed in DDK releases following 25.3 RTM.
Affected products
- Imagination Technologies GPU DDK DDK Releases up to and including 25.3 RTM
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory