CVE-2025-13952
A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device.
The shader code contained in the web page executes a path in the compiler that held onto an out of date pointer, pointing to a freed memory object.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1059Command and Scripting Interpreterexecution75 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation70 %
Vulnerabilidad de use-after-free (CWE-416) en compilador GPU accesible remotamente sin autenticación (AV:N/PR:N/UI:N), explotable vía página web con shader malicioso. Permite ejecución de código y, en plataformas con privilegios del compilador, escalada.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-416
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-13952",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-13952",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-26T15:11:28.356805Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
"affectedData": [
{
"vendor": "Imagination Technologies",
"product": "Graphics DDK",
"versions": [
{
"status": "unaffected",
"version": "1.17 RTM",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.18 RTM",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "23.2 RTM",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "24.1 RTM",
"versionType": "custom",
"lessThanOrEqual": "24.2 RTM"
},
{
"status": "affected",
"version": "25.1 RTM",
"versionType": "custom",
"lessThanOrEqual": "25.2 RTM"
},
{
"status": "unaffected",
"version": "25.3 RTM",
"versionType": "custom"
}
],
"platforms": [
"Linux",
"Android"
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-01-24T03:16:00.360",
"references": [
{
"url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
"tags": [
"Vendor Advisory"
],
"source": "367425dc-4d06-4041-9650-c2dc6aaa27ce"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device.\n\nThe shader code contained in the web page executes a path in the compiler that held onto an out of date pointer, pointing to a freed memory object."
},
{
"lang": "es",
"value": "Una página web que contiene código de sombreador de GPU inusual se carga desde Internet en el proceso del compilador de GPU y desencadena un fallo de escritura de uso después de liberación en la librería del compilador de sombreadores de GPU. En ciertas plataformas, cuando el proceso del compilador tiene privilegios de sistema, esto podría permitir explotaciones adicionales en el dispositivo.\n\nEl código de sombreador contenido en la página web ejecuta una ruta en el compilador que mantenía un puntero obsoleto, apuntando a un objeto de memoria liberado."
}
],
"lastModified": "2026-06-17T08:35:02.307",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99A33CBA-49C5-4976-B668-88F87F0FF575",
"versionEndExcluding": "25.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "367425dc-4d06-4041-9650-c2dc6aaa27ce"
}