CVE-2026-22166: Imaginationtech Ddk
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.
Affected products
- Imaginationtech Ddk: up to and including 25.2; version 25.3 only
Published 2026-05-01. Last modified 2026-06-17.