CVE-2026-22166Disclosure(imaginationtech / ddk)

LOWCVSS 8.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ddk

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-10)
  • 5 total mentions across 2 days

Affected systems

Products
ddk

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-01: 1Mentions · 2026-05-10: 4Technical Details · 2026-05-01: 1Technical Details · 2026-05-10: 305-0105-10
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-011
Disclosure1
2026-05-104
Disclosure3General1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-22166 (CVSS 9.6) — multiple products. CVE: CVE-2026-22166 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This post announces the critical advisory for CVE-2026-22166, highlighting its CVSS 9.6 score and severity across multiple products. No exploits, PoC, or patch information is provided.

    1000023
    197 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22166 A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On … https://www.cve.org/CVERecord?id=CVE-2026-22166

    Post summary

    The snippet provides technical details on CVE-2026-22166—including a write UAF crash via WebGPU content in GPU GLES—but does not mention a PoC, exploitation, patch, or false positives.

    00010112
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-22166-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely directs to a research advisory URL and includes generic hashtags, offering no substantive details about the CVE beyond its reference.

    0000011
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-22166 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory confirms CVE-2026-22166 as a critical vulnerability with a CVSS score of 9.6, but it does not provide a PoC, exploit, active exploitation evidence, or patch information.

    0000032
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-22166 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES…

    Post summary

    The text announces CVE-2026-22166, describing a critical WebGPU UAF crash with associated CVSS score and advisory status, but provides no PoC, exploit, or patch details.

    0000030
    197 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appimaginationtechddk---
Appimaginationtechddk25.3--

Explore more