CVE-2026-22166: Imaginationtech Ddk

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.

Affected products

Published 2026-05-01. Last modified 2026-06-17.