Junglewise Threat Intelligence

CVE-2026-45196: Imagination Technologies Graphics DDK privilege escalation in GPU Firmware

CVE-2026-45196 · Severity: info · CVSS 0 · Published 2026-07-10

Technologies: Imagination Technologies Graphics DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in the Imagination Technologies Graphics DDK allows software running within a virtual machine to send unauthorized commands to the GPU firmware. This could allow a malicious user or compromised guest system to gain elevated privileges on the host device. Such an exploit could compromise the security of the entire platform, potentially leading to unauthorized data access or full system control.

Technical details

An improper handling of permissions (CWE-280) in the Imagination Technologies Graphics DDK allows kernel-mode software within a guest virtual machine to issue malicious commands to the GPU firmware. These commands can trigger unauthorized GPU register access. An attacker with kernel-level access inside a VM can leverage this to achieve privilege escalation on the host system. The vulnerability affects various versions of the Graphics DDK on Linux and Android platforms, specifically up to version 26.1 RTM1. A fix is available in version 26.1 RTM2.

Affected products

  • Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 to 25.3 RTM, 26.1 RTM1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats