A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable further exploits on the device.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
|
History
Fri, 01 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable further exploits on the device. | |
| Title | GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs | |
| Weaknesses | CWE-416 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: imaginationtech
Published:
Updated: 2026-05-01T19:24:51.079Z
Reserved: 2026-01-06T15:50:36.205Z
Link: CVE-2026-22165
No data.
Status : Received
Published: 2026-05-01T16:16:29.437
Modified: 2026-05-01T16:16:29.437
Link: CVE-2026-22165
No data.
OpenCVE Enrichment
No data.
Weaknesses