CVE-2026-41157: Imagination Technologies Graphics Ddk
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash. The software computes a required memory size from untrusted input, but integer overflow can produce a value smaller than needed. Subsequent write operations may then occur past the intended memory boundary, corrupting adjacent memory and causing process instability or termination.
Affected products
- Imagination Technologies Graphics Ddk: version 1.18 RTM only; version 23.2 RTM only; version 24.2 RTM only; from 25.1 RTM, up to and including 25.3 RTM; version 26.1 RTM only
Published 2026-06-12. Last modified 2026-06-17.