CVE-2026-22166 Details
Description
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.
A write use-after-free vulnerability has been identified in the GPU GLES user-space shared library of Imagination Technologies. This vulnerability is triggered by a web page containing unusual WebGPU content, which is loaded into the GPU GLES render process. The improper handling of this content can cause a crash in the shared library. On certain platforms, if the process executing the graphics workload has system privileges, this vulnerability could be exploited to perform further actions on the device.
The DDK GLES user-space shared library has been updated to properly manage unusual WebGPU execution patterns, preventing disruptions in the rendering process. Users should ensure they are using a version of the DDK that includes this update.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| imaginationtech ddk | <= 25.2 25.3 rtm |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | New CVE Received | imaginationtech |