CVE-2026-22166

CVE-2026-22166: GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable

Vendor Imagination Technologies
Product Graphics DDK
Weakness CWE-416
Published May 1, 2026
Last update May 1, 2026

CVSS base score

What the vulnerability does

01Description

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.

Key dates

02Disclosure timeline

May 1, 2026 CVE published
May 1, 2026 Record updated