CVE-2026-22166
8.1Imagination Technologies · Graphics DDK
A use-after-free vulnerability in Imagination Technologies Graphics DDK allows an authenticated user to trigger a memory corruption crash via malicious WebGPU content.
Executive summary
A use-after-free vulnerability in the Imagination Technologies Graphics DDK affects multiple graphics driver versions and creates a severe risk of integrity and availability compromise.
Vulnerability
This vulnerability is a Use After Free (CWE-416) within the GPU GLES user-space shared library, triggered by loading unusual WebGPU content via a low-privileged user interaction.
Business impact
A successful exploit can result in complete loss of data integrity and system availability for the affected host. When the graphics workload executes with system privileges, this flaw could facilitate privilege escalation and subsequent system compromise. With a CVSS score of 8.1, the high severity reflects the potential for severe operational disruption and unauthorized system control.
Remediation
Immediate Action: Update the Imagination Technologies Graphics DDK to version 26.1 RTM or later where the vulnerability is resolved.
Proactive Monitoring: Monitor system logs for unexpected graphics driver crashes, rendering process restarts, or anomalous user-space errors.
Compensating Controls: Restrict untrusted web browsing and rendering content on critical systems where immediate driver updates are not feasible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for severe system impact when combined with elevated driver privileges, organizations must prioritize updating the affected graphics drivers. Apply the vendor security updates immediately to eliminate the use-after-free risk and protect endpoints from potential code execution scenarios.