Ghostwire

CVE-2026-22166: A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash...

HIGH CVSS 7.5

Published: May 1, 2026 | Last Modified: May 1, 2026

Description

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References