CVE-2026-22165: Imaginationtech Ddk

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable further exploits on the device.

Affected products

Published 2026-05-01. Last modified 2026-06-17.