By vendor
Imaginationtech vulnerabilities
Known CVEs affecting Imaginationtech products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-45195HIGH 7.8
A vulnerability in Imagination Technologies' GPU driver (DDK) allows a local user with basic privileges to send specially crafted commands to the GPU firmware that bypass memory access controls. This can result in reading or writing to memory regions outside what the kernel should be permitted to access, potentially enabling privilege escalation or data theft on systems running affected GPU drivers.
- CVE-2026-21734HIGH 7.7
A vulnerability in the GPU shader compiler library can be triggered when a malformed web page containing specially crafted GPU shader code is loaded and processed. The compiler crashes due to an out-of-bounds memory write when handling an edge case involving a very small value in the shader code. On systems where the compiler runs with elevated privileges, this crash could potentially be chained with additional exploits to compromise the device. The vulnerability does not grant direct access to sensitive data, but the ability to crash a privileged process with controlled memory corruption creates a meaningful attack surface.