CVE-2019-16508: Google Chrome OS

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.

Affected products

  • Google Chrome OS: before r74-11895.b (fixed in r74-11895.b); from r75, before r75.12105.b (fixed in r75.12105.b); from r76, before r76.12208.0.0 (fixed in r76.12208.0.0)

Published 2019-10-01. Last modified 2026-06-17.