Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5520 articles · 213524 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-41157EXPLOITEDPATCHED
google · chrome

GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D

Description

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash. The software computes a required memory size from untrusted input, but integer overflow can produce a value smaller than needed. Subsequent write operations may then occur past the intended memory boundary, corrupting adjacent memory and causing process instability or termination.

Affected Products

VendorProductVersions
googlechrome1.18 RTM, 23.2 RTM, 24.2 RTM, 25.1 RTM, 26.1 RTM

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googleandroidcert_advisory90%
lenovolenovo computercert_advisory90%

References

  • https://www.imaginationtech.com/gpu-driver-vulnerabilities/

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] Android Patchday September 2026: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB89d ago
CVE-2026-41157 | Imagination Graphics DDK up to 26.1 RTM GPU user-space Driver out-of-bounds write
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
26.2 RTM
CWECWE-787, CWE-20
PublishedJun 12, 2026
Last enriched89d agov2
Tags
code executiondenial of serviceinformation disclosuredata manipulation
Trending Score66
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85046EXPKEV
CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
Trending: 146
HIGHCVE-2026-87491EXPKEV
CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code in
Trending: 137
CRITICALCVE-2026-49921
CVE-2026-49921: In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote
Trending: 51
CRITICALCVE-2026-58822
CVE-2026-58822: In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to
Trending: 51
HIGHCVE-2026-34192EXP
GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 12, 2026
Discovered by ZDM
Jun 12, 2026
Updated: severity, affectedVersions, activelyExploited
Jun 13, 2026
Actively Exploited
Jun 16, 2026
Patch Available
Jun 16, 2026

Version History

v2
Last enriched 89d ago
v2Tier C89d ago

Updated severity to CRITICAL, added affected version 25.3 RTM, and marked the vulnerability as actively exploited.

severityaffectedVersionsactivelyExploited
via VulDB
v189d ago

Initial creation