Executive brief
A vulnerability in the Imagination Technologies Graphics DDK (Driver Development Kit) allows a non-privileged user to gain unauthorized access to physical memory. By running a malicious application that makes specific improper calls to the graphics processor (GPU), an attacker can bypass security boundaries to read or write sensitive data. This could lead to a total compromise of the device's memory, potentially exposing user data or allowing for further system-level attacks.
Technical details
A use-after-free (UAF) vulnerability exists in the Memory Management Unit (MMU) mapping logic of the Imagination Technologies Graphics DDK. A local, non-privileged attacker can trigger a failure path in the MMU mapping logic through a specific sequence of improper GPU system calls. This results in incomplete cleanup of internal driver state, facilitating unauthorized access to physical memory from shader code. The vulnerability affects Linux and Android platforms using specific DDK versions. A fix is available in version 26.1 RTM2.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 through 25.3 RTM, 26.1 RTM1
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory