Imagination Technologies maintains graphics and multimedia intellectual property that, despite a narrow product scope, reaches deeply embedded deployment across mobile devices, consumer electronics, and specialized computing platforms through its PowerVR GPU architectures and related development tooling. The vendor's vulnerability footprint concentrates in its Driver Development Kit and skews toward serious outcomes, with a meaningful share of disclosures reaching critical severity and reflecting the memory-safety and privilege-boundary demands of kernel-level graphics drivers. The recurring weakness classes—use-after-free conditions, improper privilege management, memory-buffer overflows, and resource-exposure flaws—are characteristic of low-level driver code where direct hardware access and kernel integration amplify the impact of memory and access-control failures. Defenders should prioritize graphics-driver updates as part of broader mobile and embedded device patching cycles, since the attack surface spans billions of devices carrying the vendor's GPU technology. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imagination Technologies over time
Of all the CVEs published by Imagination Technologies as a CNA, 30.7% affect products that Imagination Technologies develops as a vendor.
Of all the CVEs published that affect products developed by Imagination Technologies, 95.8% are self-published by Imagination Technologies as a CNA.
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13952CRITICAL A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. | Jan 24, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-21734HIGH A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On ce | Jun 26, 2026 | 7.7 | 32 | NO | NO |
CVE-2026-22166HIGH A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platfo | May 1, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-45195HIGH Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for th | Jun 26, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-22165HIGH A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain plat | May 1, 2026 | 8.1 | 31 | NO | NO |
CVE-2025-58411HIGH Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free | Jan 13, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-22167HIGH Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages.
Under certain circumstances t | May 1, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-21732CRITICAL A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On ce | Mar 20, 2026 | 9.6 | 30 | NO | NO |
CVE-2025-25176CRITICAL Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform. | Jan 13, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-22163HIGH Requires malware code to misuse the DDK kernel module IOCTL interface.
Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to | Mar 20, 2026 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imagination Technologies.
Media articles that mention a CVE ID that affects a product developed by Imagination Technologies — matched by CVE ID, not by vendor name.