CVE Database
/

CVE-2026-22166

Back to search

CVE-2026-22166

Published: May 1, 2026

Modified: May 1, 2026

PUBLISHED

Description

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.

VendorProductVersions

Imagination Technologies

Graphics DDK

affected
1.18 RTM
affected
23.2 RTM
affected
24.1 RTM - <= 24.2 RTM
affected
25.1 RTM - <= 25.3 RTM
unaffected
26.1 RTM

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now